• DocumentCode
    2418067
  • Title

    An Approach for Unifying Rule Based Deep Packet Inspection

  • Author

    Munoz, A. ; Sezer, S. ; Burns, D. ; Douglas, G.

  • Author_Institution
    Centre for Secure Inf. Technol. (CSIT), Queen´´s Univ. of Belfast, Belfast, UK
  • fYear
    2011
  • fDate
    5-9 June 2011
  • Firstpage
    1
  • Lastpage
    5
  • Abstract
    High performance Internet traffic inspection and layer-7 content analysis have become essential functions of high speed networks. Over the past decade several DPI systems have evolved targeting specific issues related to traffic management, user/application policing, intrusion detection/prevention, URL/malicious/unwanted content filtering. Snort, OpenDPI, Bro, L7-filter, ClamAV are a number of open-source tools based on custom DPI engines and custom rule-sets. The surging demand for higher bandwidth DPI systems capable of supporting larger rule-sets requires the use of hardware acceleration and hardware-based systems. In comparison to software based systems, the design and development of custom purpose hardware for DPI is expensive. The need for DPI solutions for a range of applications at high speed requires a unified processing platform. This paper presents the research in converting known DPI rule-sets into a meta format based on regular expressions, that can be executed by software and hardware-based processing platforms. To demonstrate this work a Snort2Regex translator has been developed to transform Snort rules into regular expressions using not only the content of the Snort rule but every relevant element that belongs to it and could increase the accuracy of the analysis.
  • Keywords
    Internet; computer network management; computer network security; inspection; public domain software; telecommunication traffic; Bro; ClamAV; Internet traffic inspection; L7-filter; OpenDPI; Snort2Regex translator; URL content filtering; application policing; hardware acceleration; hardware-based processing platform; hardware-based system; high speed network; intrusion detection; intrusion prevention; layer-7 content analysis; malicious content filtering; meta format; open-source tools; rule based deep packet inspection; software-based processing platform; traffic management; unwanted content filtering; user policing; Hardware; IP networks; Internet; Intrusion detection; Payloads; Protocols; Syntactics;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Communications (ICC), 2011 IEEE International Conference on
  • Conference_Location
    Kyoto
  • ISSN
    1550-3607
  • Print_ISBN
    978-1-61284-232-5
  • Electronic_ISBN
    1550-3607
  • Type

    conf

  • DOI
    10.1109/icc.2011.5963095
  • Filename
    5963095