Javascript must be enabled to continue!
Hybrid Energy-Aware Multi-Match Network Intrusion Detection System (HEAMC-NIDS)
View through CrossRef
Network Intrusion Detection Systems (NIDS) depend on accurate and high-speed packet inspection to detect malicious activity. The increasing size of Snort databases and rising network line rates challenge existing solutions, which often compromise either throughput or energy efficiency. None of the prior works have focused on integrating packet classification along with payload matching. They have optimized multi-match classification using TCAMs, rule layering, or prefix-based segmentation in payload matching, but each suffers from scalability and power consumption limitations. This paper proposes a Hybrid Energy-Aware Multi-Match NIDS (HEAMC-NIDS) thatintegrates prefix-segmented TCAM architecture, layered rule compression, and bit-map assisted aggregation for efficient signature detection. The design activates only one TCAM block per lookup, drastically reducing matchline switching and power consumption. Analytical modeling and FPGA simulation show that HEAMC-NIDS achieves 150 Gbps throughput, 90% energy reduction, and up to 70% memory savings compared with existing TCAM-based NIDS implementations.
Title: Hybrid Energy-Aware Multi-Match Network Intrusion Detection System (HEAMC-NIDS)
Description:
Network Intrusion Detection Systems (NIDS) depend on accurate and high-speed packet inspection to detect malicious activity.
The increasing size of Snort databases and rising network line rates challenge existing solutions, which often compromise either throughput or energy efficiency.
None of the prior works have focused on integrating packet classification along with payload matching.
They have optimized multi-match classification using TCAMs, rule layering, or prefix-based segmentation in payload matching, but each suffers from scalability and power consumption limitations.
This paper proposes a Hybrid Energy-Aware Multi-Match NIDS (HEAMC-NIDS) thatintegrates prefix-segmented TCAM architecture, layered rule compression, and bit-map assisted aggregation for efficient signature detection.
The design activates only one TCAM block per lookup, drastically reducing matchline switching and power consumption.
Analytical modeling and FPGA simulation show that HEAMC-NIDS achieves 150 Gbps throughput, 90% energy reduction, and up to 70% memory savings compared with existing TCAM-based NIDS implementations.
Related Results
Network Based Intrusion Detection System Using Weighted Product Model (WPM)
Network Based Intrusion Detection System Using Weighted Product Model (WPM)
A security technology called a network-based intrusion detection system (NIDS) was created to safeguard computer networks against unauthorised access and criminal activity. This te...
The Critical Role of NIDSNIPS in Protecting Internet Infrastructure
The Critical Role of NIDSNIPS in Protecting Internet Infrastructure
With the rapid development and wide application of the Internet, network security has become an important issue in modern society. Network attacks such as network worms, botnets an...
Development and application of biological intelligence technology in computer
Development and application of biological intelligence technology in computer
To study the development and application of biological intelligence technology in computers and realize high-precision network anomaly detection, a distributed intrusion detection ...
Adversarial Red Teaming for NIDS:Model-Agnostic Physical-Space Attacks
Adversarial Red Teaming for NIDS:Model-Agnostic Physical-Space Attacks
Abstract
Adversarial examples have been widely studied across domains such as image recognition and speech processing, but their implications for Network Intrusion Detectio...
Fusion of Transformer and ML-CNN-BiLSTM for Network Intrusion Detection
Fusion of Transformer and ML-CNN-BiLSTM for Network Intrusion Detection
Abstract
Network intrusion detection system (NIDS) can effectively sense network attacks, which is of great significance for maintaining the security of cyberspace. To meet...
A Framework for Detecting Distributed Denial of Services Attack in Cloud Enviorment using Machine Learning Techniques
A Framework for Detecting Distributed Denial of Services Attack in Cloud Enviorment using Machine Learning Techniques
Distributed Denial of Service (DDoS) persists in Online Applications as One of those significant threats. Attackers can execute DDoS by the more natural steps. Then with the high p...
National Identification Systems As Enablers of Online Identity
National Identification Systems As Enablers of Online Identity
This chapter examines the role of national identification systems (NIDS) as enablers of online identity in this digital age. With the rapid growth of digital services and platforms...
Intelligent FMI-Reduct Ensemble Frame Work for Network Intrusion Detection System (NIDS)
Intelligent FMI-Reduct Ensemble Frame Work for Network Intrusion Detection System (NIDS)
The era of computer networks and information systems includes finance, transport, medicine, and education contains a lot of sensitive and confidential data. With the amount of conf...

