nu-logo  list-logo   

NetShield: A Vulnerability Signature Based Network Intrusion Detection System

Summary

Accuracy and speed are the two most important metrics for Network Intrusion Detection or Prevention Systems (NIDS/NIPSes). NetShield is a vulnerability signature based NIDS/NIPS, which achieves multi-gigabit throughput while offering much better accuracy comparing to regular expression signature based NIDSes, such as Snort. NetShield uses the vulnerability signatures based on protocol semantic information. The core engine of NetShield matches thousands of vulnerability signatures at high speed.

This work is mainly conducted at Northwestern University, by the Lab for Internet and Security Technology (LIST), with colaboration from Tsinghua University, China.

Faculty and Staff

Students

Collaborators

Publications

Releases

Sponsors

This work has been supported by US NSF CNS-0831508 award and AFOSR YIP award FA9550-07-1-0074.

Feedbacks are welcome (please send email to Zhichun Li)