• DocumentCode
    166457
  • Title

    Pattern matching algorithms for intrusion detection and prevention system: A comparative analysis

  • Author

    Gupta, V. ; Singh, Monika ; Bhalla, Vinod K.

  • Author_Institution
    Comput. Sci. & Eng., Thapar Univ., Patiala, India
  • fYear
    2014
  • fDate
    24-27 Sept. 2014
  • Firstpage
    50
  • Lastpage
    54
  • Abstract
    Intrusion Detection and Prevention Systems (IDPSs) are used to detect malicious activities of intruders and also prevent from the same. These systems use signatures of known attacks to detect them. Signatures are identified through pattern matching algorithm which is the heart of IDPSs. Due to technological advancements, network speed is increasing day by day, so pattern matching algorithm to be used in IDPS should be fast enough so as to match the network speed. Therefore choice of pattern matching algorithm is the critical to the performance of IDS and IPS. Several pattern matching algorithms exist in literature, but which pattern matching algorithm will give best performance for IDPS is not known at hand. So in this work four pattern matching algorithms namely Brute-force, RabinKarp, Boyer-Moore and Knuth-Morris-Pratt has been selected for the analysis. These single keyword matching algorithms are mainly used. Performance of pattern matching algorithms is analyzed in terms of run time by varying number of patterns and by varying size of network captured (pcap) file.
  • Keywords
    pattern matching; security of data; Boyer-Moore algorithm; IDPS; Knuth-Morris-Pratt algorithm; RabinKarp algorithm; brute-force algorithm; intrusion detection and prevention systems; malicious activities; network captured file; network speed; pattern matching algorithms; technological advancements; Algorithm design and analysis; Databases; Force; Intrusion detection; Pattern matching; Protocols; Boyer-Moore; Intrusion Detection and Prevention Systems (IDPSs); Knuth-Morris-Pratt (KMP); Pattern Matching; Rabin-Karp;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Advances in Computing, Communications and Informatics (ICACCI, 2014 International Conference on
  • Conference_Location
    New Delhi
  • Print_ISBN
    978-1-4799-3078-4
  • Type

    conf

  • DOI
    10.1109/ICACCI.2014.6968595
  • Filename
    6968595