DocumentCode :
2313036
Title :
An Algorithm of Large-Scale Approximate Multiple String Matching for Network Security
Author :
Song, Tian ; Xue, Yibo ; Wang, Dongsheng
Author_Institution :
Dept. of Comput. Sci. & Technol., Tsinghua Univ., Beijing
fYear :
2006
fDate :
25-27 Oct. 2006
Firstpage :
1
Lastpage :
5
Abstract :
Payload checking has become the basic technique for network security applications, where the exact string matching technology is widely used. But as the game between attackers and defenders goes further into payload confusion, the approximate string matching technology is needed, especially large-scale approximate multiple string matching technology. In this paper, we propose one practical algorithm, LargePEX, for large scale approximate multiple string matching based on edit distance. The algorithm is basically extended from PEX, an algorithm of approximate single string matching, with the idea of filtering and verification. LargePEX is finely designed to fit for large-scale matching using fine grain steps analyses. Some experiments are presented to verify the efficiency of LargePEX. As the results show, for the set of 10k strings, the average network payload checking speed using this algorithm can achieve 25 MBps-40 MBps, enough for 100 Mbps Ethernet. With hardware upgrading, the algorithm is also practical for Gigabit Ethernet. So LargePEX provides a new way for defenders to develop more effective methods to protect valuable resources and prevent intrusions by payload checking.
Keywords :
local area networks; security of data; string matching; telecommunication security; Ethernet; LargePEX; edit distance; filtering; fine grain steps analyses; hardware upgrading; intrusion prevention; large-scale approximate multiple string matching; network security; payload checking; valuable resource protection; verification; Computer security; Ethernet networks; Filtering algorithms; Information security; Large-scale systems; National security; Pattern matching; Payloads; Protection; Sequences;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Communications and Networking in China, 2006. ChinaCom '06. First International Conference on
Conference_Location :
Beijing
Print_ISBN :
1-4244-0463-0
Electronic_ISBN :
1-4244-0463-0
Type :
conf
DOI :
10.1109/CHINACOM.2006.344838
Filename :
4149803
Link To Document :
بازگشت