Intrusion detection system designs for computer networks and their implementations in FPGA environment
2010
0 görüntülenme
0 i̇ndirme
Danışman: Doç. Dr. Yetkin Tatar
Özet (EN)
In order to ensure computer network security, researchers have been developing both software and hardware based products such as firewalls, antivirus programs, and Intrusion Detection Systems (IDS). IDSs are classifier systems deciding whether the pockets on the networks are intrusion pockets or not. In the networks with heavy traffic, fast running of IDSs and the lack of delay resources are very important. Therefore, the researches are continuing increasingly to be developed hardware based IDSs. The investigations concerning IDS are separated into two areas. One of them is to employ different classification algorithms to classify these packets quickly and correctly and the other is the improvement of hardware structure on which those algorithms will run.In this thesis, an IDS design which can run on real-time in computer networks and its implementation in FPGA (Field Programmable Gate Arrays) environment is intended. For this purpose, classification of packets which flows from network and have attack characteristics were performed according to the packet header structure using Artificial Neural Networks, Naive Bayesian and Decision Tree method. All three algorithms were trained using a predetermined training data and test data in the system and IDS's work has been observed against test data.A hardware based SOPC (System on Programmable Chip) system has been developed in Altera Cyclone III based EPC3C40F484C7N FGPA platform for IDS to work in real time. SOPC system has a MAC module which communicates with the computer network and has a soft processor. MAC module created in FPGA as hardware is configured and soft processor is programmed to create real-time IDS. Then, the software ensuring the summaries of the pockets received in real time from the network and the software performing online pocket classification with three different algorithms have been developed. The software has performed the online running of IDS, to be loaded the program memory of soft processor. With the necessary tests for the online running system, the appropriate results have been obtained.Key words: Intrusion Detection System, Embedded System, Ethernet IP MAC Core, Field Programmable Gate Array, System on Programmable Chip.
Yazar
Dr. Taner Tuncer
Bu Yayına Nasıl Atıf Yapılır
Taner Tuncer (Doctorate thesis). Intrusion detection system designs for computer networks and their implementations in FPGA environment, 2010, Fırat University.
Anahtar Kelimeler
Lisans
Tüm Hakları Saklıdır
Bu eser belirtilen lisans koşulları altında paylaşılmaktadır.
Fırat University tezlerinden daha fazlası
- Analysis in the context of entrepreneurship of factors that affect the spreading strategies of mutinational companies in the global scale(2018)
- The effect of animation supported 5E Model application on students' academic achievements and motivation(2015)
- The effect of the marble powder used as fine material on the durability of concrete(2013)
- Heating and ionization processes to lower ionosphere by lightning induced electromagnetic waves(2013)
- Color usage at Turkish Divan of Fuzûlî(2013)
- A mathematical model for determining of transport, range and distribution characteristics of uranium, thorium and potassium(2013)