L+ 1-mwm: A fast pattern matching algorithm for high-speed packet filtering

YH Choi, MY Jung, SW Seo - IEEE INFOCOM 2008-The 27th …, 2008 - ieeexplore.ieee.org
YH Choi, MY Jung, SW Seo
IEEE INFOCOM 2008-The 27th Conference on Computer Communications, 2008ieeexplore.ieee.org
A signature-based network intrusion detection system (NIDS) identifies intrusions by
comparing the data traffic with known signature patterns. In this process, matching of packet
strings against signature patterns dominates the overall system performance. The MWM
algorithm has been known as the fastest pattern matching algorithm when the patterns in a
rule set rarely appear in packets. However, the matching time does not decrease if the
length of the shortest pattern in a signature group is too short. In this paper, by extending the …
A signature-based network intrusion detection system (NIDS) identifies intrusions by comparing the data traffic with known signature patterns. In this process, matching of packet strings against signature patterns dominates the overall system performance. The MWM algorithm has been known as the fastest pattern matching algorithm when the patterns in a rule set rarely appear in packets. However, the matching time does not decrease if the length of the shortest pattern in a signature group is too short. In this paper, by extending the length of the shortest pattern, we minimize the pattern matching time of the algorithm which uses multi-byte unit. For example, when the length of the shortest pattern is less than 5, the proposed algorithm shows 38.87% enhancement in average.
ieeexplore.ieee.org
以上显示的是最相近的搜索结果。 查看全部搜索结果