北京邮电大学学报

  • EI核心期刊

北京邮电大学学报 ›› 2006, Vol. 29 ›› Issue (2): 118-122.doi: 10.13190/jbupt.200602.118.zhangzhx

• 研究报告 • 上一篇    下一篇

支持IDS的高速网络信息获取体系结构

张兆心,方滨兴,胡铭曾   

  1. 哈尔滨工业大学 计算机网络与信息安全技术研究中心
  • 出版日期:2006-04-28 发布日期:2006-04-28

An IDS-Supported Architecture of Information Capture for High-Speed Networks

ZHANG Zhao-xin, FANG Bin-xing, HU Ming-zeng   

  1. Research Center of Computer Network and Information Security Technology, Harbin Institute of Technology
  • Online:2006-04-28 Published:2006-04-28

摘要: 提出了一种针对高速网络环境的信息获取体系结构. 可扩展的网络探测模型较好地解决了不同网络带宽的适应性问题;高带宽数据流实时捕获技术、高效的多线程TCP/IP(传输控制协议/互联网络协议)协议栈,以及基于插件的PLUGINs协议还原平台,使信息的捕获与还原问题得到了根本性解决. 综合以上技术所构建的体系结构可以应用于多线路、高速网络环境下,解决检测范围大、数据流量高等问题,保证数据信息的及时性、安全性与准确性.

关键词: 零拷贝, 并行协议栈, 协议还原

Abstract: The architecture of information capture for the high-speed network environment was proposed. The different network bandwidth adaptive problem was well solved by the extensible network detection model. It has been found that real-time data stream capture from high-bandwidth networks, high-performance multi-thread TCP/IP (transmission control protocol/Internet protocol) protocol stack, and protocol analysis platform based on PLUGINs have captured and assembled the information wonderfully. The architecture integrated these technologies effectively will solve the problems such as the large-scale detection, high-speed data stream, ensuring the in-time, security and veracity of the information on multi-road and high-speed networks.

Key words: zero-copy, multi-thread transmission control protocol/Internet protocol stack, protocol analysis