• DocumentCode
    1975628
  • Title

    Efficient DFA grouping for traffic identification

  • Author

    Antonello, R. ; Fernandes, Sueli ; Santos, Aldri ; Sadok, Djamel ; Szabo, Geza

  • Author_Institution
    Fed. Univ. of Pernambuco, Recife, Brazil
  • fYear
    2012
  • fDate
    3-7 Dec. 2012
  • Firstpage
    1776
  • Lastpage
    1782
  • Abstract
    Traffic Identification is a key function performed by Internet Service Providers´ (ISP) administrators to evaluate and improve network services. However, traffic identification needs to be done in real-time and at wire speed to be useful for network tuning. Deep Packet Inspection (DPI) is widely used for identifying normal applications and attacks in the network by looking for well-known patterns within the packets. Such patterns are mostly expressed by Regular Expressions (RE), which are then evaluated by abstract machines known as Deterministic Finite Automata (DFA). Some previous studies grouped DFAs together to evaluate multiple patterns on a single DFA match´s run. Efficient grouping algorithms would combine several DFAs without exceeding the available machine´s memory. This work proposes and evaluates a new method to combine several DFAs into a single one. Additionally we compared this algorithm to state-of-the-art approaches using a compressed DFA model. Experimental results show that our algorithm generates less groups and transitions than existent algorithms.
  • Keywords
    Internet; telecommunication traffic; DFA grouping; DPI; ISP administrators; Internet service provider administrators; compressed DFA model; deep packet inspection; deterministic finite automata; machine memory; network services; regular expressions; traffic identification; Computer Networks; DFA Grouping; Deep Packet Inspection; Finite Automata; Traffic Analysis;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Global Communications Conference (GLOBECOM), 2012 IEEE
  • Conference_Location
    Anaheim, CA
  • ISSN
    1930-529X
  • Print_ISBN
    978-1-4673-0920-2
  • Electronic_ISBN
    1930-529X
  • Type

    conf

  • DOI
    10.1109/GLOCOM.2012.6503372
  • Filename
    6503372