DocumentCode :
1653738
Title :
High Speed Pattern Matching for Network IDS/IPS
Author :
Alicherry, Mansoor ; Muthuprasanna, M. ; Kumar, Vijay
Author_Institution :
Lucent Bell Labs., Murray Hill, NJ
fYear :
2006
Firstpage :
187
Lastpage :
196
Abstract :
The phenomenal growth of the Internet in the last decade and society´s increasing dependence on it has brought along, a flood of security attacks on the networking and computing infrastructure. Intrusion detection/prevention systems provide defenses against these attacks by monitoring headers and payload of packets flowing through the network. Multiple string matching that can compare hundreds of string patterns simultaneously is a critical component of these systems, and is a well-studied problem. Most of the string matching solutions today are based on the classic Aho-Corasick algorithm, which has an inherent limitation; they can process only one input character in one cycle. As memory speed is not growing at the same pace as network speed, this limitation has become a bottleneck in the current network, having speeds of tens of gigabits per second. In this paper, we propose a novel multiple string matching algorithm that can process multiple characters at a time thus achieving multi-gigabit rate search speeds. We also propose an architecture for an efficient implementation on TCAM-based hardware. We additionally propose novel optimizations by making use of the properties of TCAMs to significantly reduce the memory requirements of the proposed algorithm. We finally present extensive simulation results of network-based virus/worm detection using real signature databases to illustrate the effectiveness of the proposed scheme.
Keywords :
Internet; computer viruses; database management systems; digital signatures; optimisation; string matching; Aho-Corasick algorithm; Internet; TCAM-based hardware; multi-gigabit rate search speed; multiple string matching algorithm; network intrusion detection system; network intrusion prevention system; network-based virus/worm detection; optimization; pattern matching; security attack; signature database; string matching; Computer networks; Data security; Filtering; IP networks; Internet; Intrusion detection; Matched filters; Monitoring; Pattern matching; Payloads;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Network Protocols, 2006. ICNP '06. Proceedings of the 2006 14th IEEE International Conference on
Conference_Location :
Santa Barbara, CA
Print_ISBN :
1-4244-0593-9
Electronic_ISBN :
1-4244-0594-7
Type :
conf
DOI :
10.1109/ICNP.2006.320212
Filename :
4110291
Link To Document :
بازگشت