Logo image
A unique-pattern based pre-filtering method for rule matching of network security
Conference paper

A unique-pattern based pre-filtering method for rule matching of network security

Nen-Fu Huang, Hsien-Wei Hung and Wen-Yen Tsai
APCC 2012 - 18th Asia-Pacific Conference on Communications: ""Green and Smart Communications for IT Innovation"", pp.744-748
2012

Abstract

Deep Packet Inspection Pre-filtering Rule Matching
As a result of continually changing Internet and applications, more and more advanced features are requested to be available in the appliance for more accurately monitoring and managing the network. Therefore, modern networking appliances are equipped with the DPI (Deep Packet Inspection) technology to scan the payload of a packet. A rule (like Snort rules) may consist of several patterns with certain relationships, such as order, relative positions, and offset, etc. The system performance is usually dominated by not only the pattern matching algorithm but also the rule match processing algorithm. This paper proposes a unique-pattern based pre-filtering method for the rule matching. It is employed to filter out unwanted matches after scanning the packet payload by the pattern matching algorithm. The proposed algorithm is also implemented on different multi-core platforms to demonstrate its efficiency and performance. The experimental results indicate that the throughput is improved significantly and can be increased approximately linearly to the number of CPU cores. © 2012 IEEE.

Metrics

1 Record Views

Details

Logo image