FPGA-Based Network Traffic Security: Design and Implementation Using C5.0 Decision Tree Classifier

(整期优先)网络出版时间:2013-04-14
/ 1
Inthiswork,ahardwareintrusiondetectionsystem(IDS)modelanditsimplementationareintroducedtoperformonlinereal-timetrafficmonitoringandanalysis.TheintroducedsystemgatherssomeadvantagesofmanyIDSs:hardwarebasedfromimplementationpointofview,networkbasedfromsystemtypepointofview,andanomalydetectionfromdetectionapproachpointofview.Inaddition,itcandetectmostofnetworkattacks,suchasdenialofservices(DoS),leakage,etc.fromdetectionbehaviorpointofviewandcandetectbothinternalandexternalintrudersfromintrudertypepointofview.GatheringthesefeaturesinoneIDSsystemgiveslotsofstrengthsandadvantagesofthework.Thesystemisimplementedbyusingfieldprogrammablegatearray(FPGA),givingamoreadvantagestothesystem.AC5.0decisiontreeclassifierisusedasinferenceenginetothesystemandgivesahighdetectionratioof99.93%.