Back to Search

Performance evaluation of a field programmable gate array-based system for detecting and tracking peer-to-peer protocols on a gigabit ethernet network

AUTHOR Thomas, Brennon D.
PUBLISHER Biblioscholar (10/03/2012)
PRODUCT TYPE Paperback (Paperback)

Description

The TRacking and Analysis for Peer-to-Peer 2 (TRAPP-2) system is developed on a Xilinx ML510 FPGA. The goals of this research are to evaluate the performance of the TRAPP-2 system as a solution to detect and track malicious packets traversing a gigabit Ethernet network. The TRAPP-2 system detects a BitTorrent, Session Initiation Protocol (SIP), or Domain Name System (DNS) packet, extracts the payload, compares the data against a hash list, and if the packet is suspicious, logs the entire packet for future analysis. Results show that the TRAPP-2 system captures 95.56% of BitTorrent, 20.78% of SIP INVITE, 37.11% of SIP BYE, and 91.89% of DNS packets of interest while under a 93.7% network utilization (937 Mbps). For another experiment, the contraband hash list size is increased from 1,000 to 131,072,000 unique items. The experiment reveals that each doubling of the hash list size results in a mean increase of approximately 16 central processing unit cycles. These results demonstrate the TRAPP-2 system's ability to detect traffic of interest under a saturated network utilization while maintaining large contraband hash lists.
Show More
Product Format
Product Details
ISBN-13: 9781249584056
ISBN-10: 1249584051
Binding: Paperback or Softback (Trade Paperback (Us))
Content Language: English
More Product Details
Page Count: 152
Carton Quantity: 28
Product Dimensions: 7.44 x 0.33 x 9.69 inches
Weight: 0.63 pound(s)
Feature Codes: Illustrated
Country of Origin: US
Subject Information
BISAC Categories
Education | General
Descriptions, Reviews, Etc.
publisher marketing

The TRacking and Analysis for Peer-to-Peer 2 (TRAPP-2) system is developed on a Xilinx ML510 FPGA. The goals of this research are to evaluate the performance of the TRAPP-2 system as a solution to detect and track malicious packets traversing a gigabit Ethernet network. The TRAPP-2 system detects a BitTorrent, Session Initiation Protocol (SIP), or Domain Name System (DNS) packet, extracts the payload, compares the data against a hash list, and if the packet is suspicious, logs the entire packet for future analysis. Results show that the TRAPP-2 system captures 95.56% of BitTorrent, 20.78% of SIP INVITE, 37.11% of SIP BYE, and 91.89% of DNS packets of interest while under a 93.7% network utilization (937 Mbps). For another experiment, the contraband hash list size is increased from 1,000 to 131,072,000 unique items. The experiment reveals that each doubling of the hash list size results in a mean increase of approximately 16 central processing unit cycles. These results demonstrate the TRAPP-2 system's ability to detect traffic of interest under a saturated network utilization while maintaining large contraband hash lists.
Show More
Your Price  $68.82
Paperback