Logo image
Next Generation Embedded Network Security Systems
Dissertation

Next Generation Embedded Network Security Systems

Kao, Chia-nan
Doctor of Philosophy (PHD), 國立清華大學, 通訊工程研究所
2014

Abstract

嵌入式系統 網路入侵偵測 網路病毒掃描 Botnet偵測 Embedded System Network Intrusion Detection System Network Anti-virus Botnet Detection
In general, the problems for current embedded network security systems are limited computing resources and numerous matching rules. By the statistics of OpenWrt, most SME/SOHO routers are embedded network systems and their memory sizes are usually lower than 64 MB. With the exponential growth of Malware/virus, anti-virus and intrusion detection industries employ automatic rule-generating (RuleGen) systems. However, the numerous security rules (IPs, domain names, URLs, file checksums and string-based patterns) generated by RuleGen systems are difficult to be utilized by the resource-limited SME/SOHO routers. For dealing with the problems, some software-based refined matching methods for embedded systems were proposed. They are a software-based MD5-checksum lookup scheme, a network fast virus-scanning scheme, a large-scale Botnet IP lookup scheme, and a retargetable multiple-string-matching code-generating system. They can improve the performance and capacity of resource-limit SME/SOHO routers for IP, MD5 file checksum, and string-based rules. The software-based MD5-checksum lookup scheme can maintain a high lookup speed by removing unnecessary table searches. The network fast virus-scanning scheme is a proxyless stream-Based anti-virus architecture for network virus scan with zero buffering. The architecture can eliminate the buffering I/O operations in old store-and-forward architectures and get better performance. The large-scale Botnet IP lookup scheme can utilize the CPU cache to obtain a good performance for large-scale IP matching. The retargetable multiple-string-matching code-generating system presents the interfaces to co-design with hardware and obtain better performance in text-based pattern matching for embedded environments. Finally, for exploring the possibility to refine the RuleGen systems for resource-limit SME/SOHO routers, a simple HTTP-like Botnet rule-generating system is proposed.

Metrics

1 Record Views

Details

Logo image