The Experts below are selected from a list of 2901 Experts worldwide ranked by ideXlab platform
Cliff C. Zou - One of the best experts on this subject based on the ideXlab platform.
-
A Chipset Level network Backdoor: Bypassing Host-Based Firewall & IDS
2010Co-Authors: Sherri Sparks, Shawn Embleton, Cliff C. ZouAbstract:Chipsets refer to a set of specialized chips on a computer's motherboard or an expansion card [12]. In this paper we present a proof of concept chipset level rootkit/network backdoor. It interacts directly with network interface card hardware based on a widely deployed Intel chipset 8255x, and we tested it successfully on two different Ethernet cards with this chipset. The network backdoor has the ability to both covertly send out packets and receive packets, without the need to disable security software installed in the compromised host in order to hide its presence. Because of its low-level position in a computer system, the backdoor is capable of bypassing virtually all commodity firewall and host-based intrusion detection software, including popular, widely deployed applications like Snort and Zone Alarm Security Suite. Such network backdoors, while complicated and hardware specific, are likely to become serious threats in high profile attacks like corporate espionage or cyber terrorist attacks
-
a chipset level network backdoor bypassing host based firewall ids
Computer and Communications Security, 2009Co-Authors: Sherri Sparks, Shawn Embleton, Cliff C. ZouAbstract:Chipsets refer to a set of specialized chips on a computer's motherboard or an expansion card [12]. In this paper we present a proof of concept chipset level rootkit/network backdoor. It interacts directly with network interface card hardware based on a widely deployed Intel chipset 8255x, and we tested it successfully on two different Ethernet cards with this chipset. The network backdoor has the ability to both covertly send out packets and receive packets, without the need to disable security software installed in the compromised host in order to hide its presence. Because of its low-level position in a computer system, the backdoor is capable of bypassing virtually all commodity firewall and host-based intrusion detection software, including popular, widely deployed applications like Snort and Zone Alarm Security Suite. Such network backdoors, while complicated and hardware specific, are likely to become serious threats in high profile attacks like corporate espionage or cyber terrorist attacks.
David A Daniel - One of the best experts on this subject based on the ideXlab platform.
-
terabit ethernet access and core switching using time space carrier sensing
IEEE Systems Journal, 2010Co-Authors: Joseph Y Hui, David A DanielAbstract:We propose an Ethernet architecture for local access and switching of Internet traffic. To achieve Terabit or Petabit switching, both time (high transmission speed) and space (multistage interconnection network) technologies are required. The Ethernet is both time and space carrier sensed, extending CSMA/CD to a time-space protocol called CSMA/TS. We call the space-time transmission medium Terabit Ethernet (TbE). We focus on the 3-stage Clos network, treating the first stage as an access switch and the second stage as the core switch. Space time carrier sensing allows routing in the TbE by the network interface card (NIC). The advantages are scalability, lower cost, and most importantly, reduced delay end-to-end. Simple analysis is given for evaluating throughput for the access switch, as well as for 2-stage and 3-stage TbE networks.
-
terabit ethernet a time space carrier sense multiple access method
Global Communications Conference, 2008Co-Authors: Joseph Y Hui, David A DanielAbstract:To achieve Terabit and Petabit switching, both time (high transmission speed) and space (multi-stage interconnection network) technologies are required. We propose an Ethernet for which for both time and space are carrier sensed. We extend CSMA/CD to a time- space protocol called CSMA/TS. We call the space-time transmission medium Terabit Ethernet (TbE). This space sensing CSMA/TS protocol allows routing in ether to be done by the network interface card (NIC). The advantages are scalability, lower cost, and most importantly, reduced delay end-to-end. Simple analysis is given for evaluating throughput for 2-stage and 3-stage TbE networks.
Shiwen Mao - One of the best experts on this subject based on the ideXlab platform.
-
csi phase fingerprinting for indoor localization with a deep learning approach
IEEE Internet of Things Journal, 2016Co-Authors: Xuyu Wang, Lingjun Gao, Shiwen MaoAbstract:With the increasing demand of location-based services, indoor localization based on fingerprinting has become an increasingly important technique due to its high accuracy and low hardware requirement. In this paper, we propose PhaseFi, a fingerprinting system for indoor localization with calibrated channel state information (CSI) phase information. In PhaseFi, the raw phase information is first extracted from the multiple antennas and multiple subcarriers of the IEEE 802.11n network interface card by accessing the modified device driver. Then a linear transformation is applied to extract the calibrated phase information, which we prove to have a bounded variance. For the offline stage, we design a deep network with three hidden layers to train the calibrated phase data, and employ the weights of the deep network to represent fingerprints. A greedy learning algorithm is incorporated to train the weights layer-by-layer to reduce computational complexity, where a subnetwork between two consecutive layers forms a restricted Boltzmann machine. In the online stage, we use a probabilistic method based on the radial basis function for online location estimation. The proposed PhaseFi scheme is implemented and validated with extensive experiments in two representation indoor environments. It is shown to outperform three benchmark schemes based on CSI or received signal strength in both scenarios.
-
Phasefi: phase fingerprinting for indoor localization with a deep learning approach
2015 IEEE Global Communications Conference GLOBECOM 2015, 2015Co-Authors: Xuyu Wang, Lingjun Gao, Shiwen MaoAbstract:With the increasing demand of location-based services, indoor localization based on fingerprinting has become an increasingly important technique due to its high accuracy and low hardware requirement. In this paper, we propose PhaseFi, a fingerprinting system for indoor localization with calibrated channel state information (CSI) phase information. In PhaseFi, the raw phase information is first extracted from the multiple antennas and multiple subcarriers of the IEEE 802.11n network interface card (NIC) by accessing the modified driver. Then a linear transform is used to extract the calibrated phase information, which is proven to have a bounded variance. For the offline stage, we design a deep network with three hidden layers to train the calibrated phase data, and employ weights to represent fingerprints. A greedy learning algorithm is incorporated to train the weights layer-by-layer to reduce computational complexity, where a sub-network between two continuous layers forms a Restricted Boltzmann Machine (RBM). In the online stage, we use a probabilistic method based on the radial basis function (RBF) for online location estimation. The proposed PhaseFi scheme is implemented and validated with intensive experiments in two representation indoor environments. It outperforms other three benchmark schemes based on CSI or RSS in both scenarios.
Kubálek Jan - One of the best experts on this subject based on the ideXlab platform.
-
High-Speed Packet Data DMA Transfers to FPGA
Vysoké učení technické v Brně. Fakulta informačních technologií, 2020Co-Authors: Kubálek JanAbstract:Tato práce se zabývá návrhem, implementací, testováním a měřením firmwarového modulu pro čip FPGA, který zajišťuje DMA přenosy síťových dat z RAM počítače do samotného čipu na síťové kartě. Tyto přenosy jsou prováděny přes sběrnici PCIe rychlostí až 100Gb/s s možností podpory rychlostí 200 Gb/s a 400 Gb/s. Cílem této technologie je umožnit zpracování síťového provozu za účelem údržby páteřních uzlů sítě a datových center. Modul je současně navržen tak, aby jej bylo možné použít na různých typech FPGA čipů a to především od firem Xilinx a Intel.This thesis deals on the design, implementation, testing and measuring of a firmware module for FPGA chips, which enables DMA transfers of network data from computer RAM to the FPGA chip placed on a network interface card. These transfers are carried out using a PCIe bus on the speed of up to 100 Gbps with the possible support of speeds 200 Gbps and 400 Gbps. The goal of this technology is to allow network data processing for the purpose of maintenance of backbone network nodes and data centers. The module is designed so it can be used on different types of FPGA chips, mainly those produced by companies Xilinx and Intel.
-
High-Speed Packet DMA Transfers from FPGA
Vysoké učení technické v Brně. Fakulta informačních technologií, 2018Co-Authors: Kubálek JanAbstract:Computer network devices that implement data-flow monitoring to allow network manage-ment require a high-speed receiving of a large amount of data for analysis. For a deviceto enable the monitoring of a network with high data traffic, its network interface cardneeds to be capable of transferring received data to a RAM at high speed. A new mo-dule for an FPGA chip on a network interface card, which can control these transfers, wasdesigned, implemented and tested in the course of this thesis. The created module sup-ports transfer of packets from the FPGA to the computer's memory via a PCI-Express busat the speed of 100 Gb/s and 200 Gb/s. Packets are transferred by DMA in system DPDK
-
High-Speed Packet DMA Transfers from FPGA
Vysoké učení technické v Brně. Fakulta informačních technologií, 2018Co-Authors: Kubálek JanAbstract:Pro zařízení, která na počítačových sítích zajišťují monitorování provozu a umožňují údržbusítě, může být problémem nedostatečná rychlost přijímání dat pro analýzu. Aby dokázalozařízení monitorovat síť s vysokou datovou propustností, musí být síťová karta zařízeníschopna přijatá data rychle přenášet do paměti RAM. V rámci této práce byl provedennávrh, implementace a testování modulu pro FPGA čip na síťové kartě, který tyto přenosyřídí. Vytvořený modul podporuje přenášení paketů přes sběrnici PCI-Express na rychlosti100 Gb/s a 200 Gb/s. Tyto přenosy jsou prováděny jako přenosy DMA v systému DPDK.Computer network devices that implement data-flow monitoring to allow network manage-ment require a high-speed receiving of a large amount of data for analysis. For a deviceto enable the monitoring of a network with high data traffic, its network interface cardneeds to be capable of transferring received data to a RAM at high speed. A new mo-dule for an FPGA chip on a network interface card, which can control these transfers, wasdesigned, implemented and tested in the course of this thesis. The created module sup-ports transfer of packets from the FPGA to the computer's memory via a PCI-Express busat the speed of 100 Gb/s and 200 Gb/s. Packets are transferred by DMA in system DPDK.
D L Schuff - One of the best experts on this subject based on the ideXlab platform.
-
design alternatives for a high performance self securing ethernet network interface
International Parallel and Distributed Processing Symposium, 2007Co-Authors: D L SchuffAbstract:This paper presents and evaluates a strategy for integrating the Snort network intrusion detection system into a high-performance programmable Ethernet network interface card (NIC), considering the impact of several possible hardware and software design choices. While currently proposed ASIC, FPGA, and TCAM systems can match incoming string content in real-time, the system proposed also supports the stream reassembly and HTTP content transformation capabilities of Snort. This system, called LineSnort, parallelizes Snort using concurrency across TCP sessions and executes those parallel tasks on multiple low-frequency pipelined RISC processors embedded in the NIC. LineSnort additionally exploits opportunities for intra-session concurrency. The system also includes dedicated hardware for high-bandwidth data transfers and for high-performance string matching.