Logo image
A non-computational intensive pre-filter for pattern matching in network intrusion detection systems
Conference paper

A non-computational intensive pre-filter for pattern matching in network intrusion detection systems

Nen-Fu Huang, Yen-Ming Chu, Yih-Jou Tzang, Jian-Lin Chen, Hsien-Wei Hun, Ming-Chang Shih and Chia-Nan Kao
GLOBECOM - IEEE Global Telecommunications Conference, 4150924
2006

Abstract

Intrusion detection Network security Search filter String matching
Pattern or string matching algorithm is one of the most critical tasks in the design of a high-speed network intrusion detection system (NIDS). In this paper, an efficient pre-filtering algorithm, called Super-Symbol Filter (SSF), is proposed to filter the normal traffic before they are forwarded to a pattern matching algorithm. The proposed SSF algorithm uses a tiny data structure, and is light-computational and cache-resident. It can be implemented efficiently in a software-based platform. Experimental results show that with Snort's patterns, the computation time of the SSF with the AC algorithm to process the Defcon9 trace is only one-third to half of that of a pure AC algorithm. Thus, the speed gain of the proposed scheme is around 100-300%. © 2006 IEEE.

Metrics

1 Record Views

Details

Logo image