2004
DOI: 10.1007/978-3-540-30117-2_32
|View full text |Cite
|
Sign up to set email alerts
|

A Modular System for FPGA-Based TCP Flow Processing in High-Speed Networks

Abstract: Abstract. Field Programmable Gate Arrays (FPGAs) can be used in Intrusion Prevention Systems (IPS) to inspect application data contained within network flows. An IPS operating on high-speed network traffic can be used to stop the propagation of Internet worms and to protect networks from Denial of Services (DoS) attacks. When used in the backbone of a core network, the device will be exposed to millions of active flows simultaneously. In order to protect the data in each connection, network devices will need t… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
1
1
1
1

Citation Types

0
27
0

Year Published

2005
2005
2014
2014

Publication Types

Select...
5
2

Relationship

0
7

Authors

Journals

citations
Cited by 44 publications
(27 citation statements)
references
References 13 publications
0
27
0
Order By: Relevance
“…A photograph of the system is shown in Figure 2. One FPX performed Transmission Control Protocol/Internet Protocol (TCP/IP) processing of data [3], a second FPX implemented the student's content processing circuit, and a third FPX captured traffic. Three Gigabit Ethernet line cards were used: one sent and received traffic to the student PC located anywhere on the Internet, a second Gigabit Ethernet line card sent and received data to and from the content host, and a third Gigabit Ethernet line card monitored traffic statistics.…”
Section: Network Processing Platformmentioning
confidence: 99%
“…A photograph of the system is shown in Figure 2. One FPX performed Transmission Control Protocol/Internet Protocol (TCP/IP) processing of data [3], a second FPX implemented the student's content processing circuit, and a third FPX captured traffic. Three Gigabit Ethernet line cards were used: one sent and received traffic to the student PC located anywhere on the Internet, a second Gigabit Ethernet line card sent and received data to and from the content host, and a third Gigabit Ethernet line card monitored traffic statistics.…”
Section: Network Processing Platformmentioning
confidence: 99%
“…We will use this exporter to compare the results of the new system with existing flow monitoring solutions [2,20]. Since the flow monitoring is frequently used for high-speed network monitoring [12,17,24], we need to design our flow exporter to handle such speeds. The processing of application protocols makes this task even more challenging, since each packet needs to be analyzed more thoroughly to gain the necessary information.…”
mentioning
confidence: 99%
“…These engines can perform a variety of tasks, such as calculating checksums or handling segmentation and reassembly [8,9]. Earlier work has demonstrated full implementation of TCP/IP on platform FPGA based systems, including the use of offload engines combined with use of the embedded processor.…”
Section: Web Server Functionsmentioning
confidence: 99%