DocumentCode :
1980451
Title :
Skip Finite Automaton: A Content Scanning Engine to Secure Enterprise Networks
Author :
Jiang, Junchen ; Tang, Yi ; Liu, Bin ; Xu, Yang ; Wang, Xiaofei
Author_Institution :
Inst. for Theor. Comput. Sci., Tsinghua Univ., Beijing, China
fYear :
2010
fDate :
6-10 Dec. 2010
Firstpage :
1
Lastpage :
5
Abstract :
Today´s file sharing networks are creating potential security problems to enterprise networks, i.e., the leakage of confidential documents. In order to prevent such leakage, we propose the Data Leakage Prevention System (DLPS) which is applied at the entrance of the enterprise network to filter out the outgoing sensitive information. The DLPS is based on a content scanning engine which defines a new type of matching problem, called longest overlap matching which also exits in many other applications as a basic problem where contents are delivered by small blocks. We study the problem by comparing it with the traditional pattern matching problem in Deep Packet Inspection (DPI) of Network Intrusion Detection Systems (NIDS) whose solutions are based on finite automata. We develop a new finite automata representation called Skip-Finite Automata (Skip-FA) which detects the packets carrying sensitive information by using default transitions to implicitly track the overlapping parts between packets´ payloads and sensitive files. The simulation results shows that our system achieves a matching speed of about 10B+ per memory access for small file set (>;20KB) and 100B+ per memory access for large file set (>;2500KB). We also find that the memory consumption of Skip-FA is almost the same to that of the original files.
Keywords :
finite automata; peer-to-peer computing; security of data; telecommunication security; content scanning engine; data leakage prevention system; deep packet inspection; file sharing network; finite automata representation; network intrusion detection system; pattern matching problem; secure enterprise network; skip finite automata; skip finite automaton; Automata; Delay; Engines; IEEE Communications Society; Logic gates; Payloads; Radiation detectors;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Global Telecommunications Conference (GLOBECOM 2010), 2010 IEEE
Conference_Location :
Miami, FL
ISSN :
1930-529X
Print_ISBN :
978-1-4244-5636-9
Electronic_ISBN :
1930-529X
Type :
conf
DOI :
10.1109/GLOCOM.2010.5683165
Filename :
5683165
Link To Document :
بازگشت