Abstract:
The paper has made research to the Linked Intrusion Prevention System based on Octeon multi-core network processor for new generation high-speed IPv6 network.,and designed a new type of prototype.The system design is based on high-speed processing on Octeon multi-core,and combines new intrusion characteristics occurred in IPv6 network.On the basis of the technique of matching rules in rule library for intrusion detection,and using the new protocol analysis and flow-based detection techniques,the different executions including control plane and data plane are distributed on multiple cores of Octeon.Adopting the mechanism of named blocks to communicate between multiple cores,and by means of the feedbacks from the cores running data plane code to the control plane core,the system has realized the high-speed linking between the flow processing,protocol analysis module and the control module,which is competent for the high-speed intrusion detection and linked prevention at Gbps level.