论文部分内容阅读
对网络中流通的数据进行截获分析是限制和打击网络黑客和网络犯罪的重要手段。然而目前基于有限状态机的截获算法由于实现成本和复杂度的限制,吞吐量较低,难以满足网络核心级的截获速度要求。该文以高速无感截获为目标,利用基于BCAM(b inary con ten t access ib le m em ory)的非状态机结构提出了一种可实现无感截获的高效易行方案。该方案从减少系统成本和实现复杂度出发,通过原创性地采用BCAM避开了设计状态机所需的复杂硬件结构,使方案更简洁高效,同时降低了系统成本,实现了汉字的高速过滤截获,能满足网络核心级,例如O c48链路速度(即2.5G b/s)无感截获系统的要求。
Intercepting and analyzing the circulating data in the network is an important means to limit and combat network hacking and cybercrime. However, due to the limitation of cost and complexity, the current state-based intercepting algorithm can not meet the intercepting speed requirement at the network core level due to the low throughput. In this paper, aiming at high speed non-inductive interception, a non-state machine architecture based on BCAM is proposed to provide an efficient and feasible solution to the problem of non-interception. The scheme starts from reducing the system cost and complexity and avoids the complex hardware structure required by the design of state machine through BCAM, which makes the scheme more concise and efficient, reduces the system cost and achieves the high-speed filtering interception , To meet the network core level, such as O c48 link speed (ie 2.5G b / s) non-inductively intercepted system requirements.