High Speed Network Intrusion Detection System (NIDS) using Low Power Precomputation Based Content Addressable Memory

  • Mythili R KIT-Kalaignarkarunanidhi Institute of Technology,Coimbatore
  • Kalpana P PSG College of Technology,Coimbatore,Tamilnadu,India


NIDS (Network Intrusion Detection Systems) plays a vital role in the security threats to computers and networks. With the onset of gigabit networks, hardware based Intrusion Detection System gains popularity because of its high performance when compared to the software-based NIDS. The software based system limits parallel execution, which in turn confines the performance of a modern network. This paper presents a signature based lookup technique using a reconfigurable hardware. Content Addressable Memory (CAM) is used as lookup table architecture to improve the speed instead of search algorithms. In order to minimize the power and to increase the speed, precomputation based CAM (PBCAM) can be used, as this technique avoids repeated search comparisons.PBCAM  employs two stage comparison with a parameter memory in the first stage and data memory in the second stage.Only the matched data in the parameter memory is compared in the data memory.This reduces the number of comparisons,thereby increasing the speed of the system.In this work dual port RAM based PBCAM (DP-PBCAM) is used to design a signature based intrusion detection system. A low power parameter extractor is used with minimum number of gates for precomputation.The hardware implementation is done using Xilinx Spartan 3E FPGA. The proposed DP-PBCAM lookups supports a gigabit speed of 7.42 Gbps.

Articles on Computers