skip to main content
10.1145/2658260.2661773acmconferencesArticle/Chapter ViewAbstractPublication PagesancsConference Proceedingsconference-collections
poster

Change-point detection method on 100 Gb/s ethernet interface

Published:20 October 2014Publication History

ABSTRACT

This paper deals with hardware acceleration of statistical methods for detection of anomalies on 100 Gb/s Ethernet. The approach is demonstrated by implementing a sequential Non-Parametric Cumulative Sum (NP-CUSUM) procedure. We use high-level synthesis in combination with emerging software defined monitoring (SDM) methodology for rapid development of FPGA-based hardware-accelerated network monitoring applications. The implemented method offloads detection of network attacks and anomalies directly into an FPGA chip. The parallel nature of FPGA allows for simultaneous detection of various kinds of anomalies. Our results show that hardware acceleration of statistical methods using the SDM concept with high-level synthesis from C/C++ is possible and very promising for traffic analysis and anomaly detection in high-speed 100 Gb/s networks.

References

  1. L. Kekely, V. Pus, and J. Korenek, "Software defined monitoring of application protocols," in INFOCOM, 2014 Proceedings IEEE. IEEE, 2014, pp. 1725--1733.Google ScholarGoogle Scholar
  2. A. G. Tartakovsky, B. L. Rozovskii, R. Blažek, and H. Kim, "A novel approach to detection of intrusions in computer networks via adaptive sequential and batch-sequential change-point detection methods," IEEE Transactions on Signal Processing, vol. 54, no. 9, pp. 3372--3382, 2006. Google ScholarGoogle ScholarDigital LibraryDigital Library
  3. H. Wang, D. Zhang, and K. Shin, "Detecting SYN flooding attacks," in INFOCOM 2002. 21st Annual Joint Conference of the IEEE Computer and Communications Societies., vol. 3, 2002, pp. 1530--1539.Google ScholarGoogle Scholar
  4. T. Cejka, "Fast TCP Flood Detector (FTFD)." {Online}. Available: http://ddd.t.cvut.cz/prj/FTFDGoogle ScholarGoogle Scholar

Index Terms

  1. Change-point detection method on 100 Gb/s ethernet interface

      Recommendations

      Comments

      Login options

      Check if you have access through your login credentials or your institution to get full access on this article.

      Sign in
      • Published in

        cover image ACM Conferences
        ANCS '14: Proceedings of the tenth ACM/IEEE symposium on Architectures for networking and communications systems
        October 2014
        274 pages
        ISBN:9781450328395
        DOI:10.1145/2658260

        Copyright © 2014 Owner/Author

        Permission to make digital or hard copies of part or all of this work for personal or classroom use is granted without fee provided that copies are not made or distributed for profit or commercial advantage and that copies bear this notice and the full citation on the first page. Copyrights for third-party components of this work must be honored. For all other uses, contact the Owner/Author.

        Publisher

        Association for Computing Machinery

        New York, NY, United States

        Publication History

        • Published: 20 October 2014

        Check for updates

        Qualifiers

        • poster

        Acceptance Rates

        ANCS '14 Paper Acceptance Rate19of57submissions,33%Overall Acceptance Rate88of314submissions,28%

      PDF Format

      View or Download as a PDF file.

      PDF

      eReader

      View online with eReader.

      eReader