DocumentCode :
2493021
Title :
Two-stage decomposition of SNORT rules towards efficient hardware implementation
Author :
Chen, Hao ; Summerville, Douglas H. ; Chen, Yu
Author_Institution :
Dept. of Electr. & Comput. Eng., SUNY - Binghamton, Binghamton, NY, USA
fYear :
2009
fDate :
25-28 Oct. 2009
Firstpage :
359
Lastpage :
366
Abstract :
The performance gap between the execution speed of security software and the amount of data to be processed is ever widening. A common solution is to close the performance gap through hardware implementation of security functions. However, continuously expanding signature databases have become a major impediment to achieving scalable hardware based pattern matching. Additionally, evolutionary rule databases have necessitated real time online updating for reconfigurable hardware implementations. Based on the observation that signature patterns are constructed from combinations of a limited number of primary patterns, we propose to decompose the Snort signature patterns. These smaller primary pattern sets can be stored along with their associations to allow dynamic signature pattern reconstruction. Not only does the matching operation potentially become more scalable, but the real time online updating task is simplified. The approach is verified with patterns from the latest version of the Snort rule database. The experimental results show that after decomposition, a reduction in size of over 77% can be achieved on Snort signature patterns.
Keywords :
digital signatures; field programmable gate arrays; pattern matching; reconfigurable architectures; FPGA; Snort rule database; Snort signature pattern; dynamic signature pattern reconstruction; evolutionary rule database; network intrusion detection system; pattern matching; reconfigurable hardware; security software; signature database; Decision support systems; Hardware; Virtual reality; Decompose; FPGAs; Finite State Machine; Network Intrusion Detection Systems (NIDS); Scalability; Security;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Design of Reliable Communication Networks, 2009. DRCN 2009. 7th International Workshop on
Conference_Location :
Washington, DC
Print_ISBN :
978-1-4244-5047-3
Electronic_ISBN :
978-1-4244-5048-0
Type :
conf
DOI :
10.1109/DRCN.2009.5339986
Filename :
5339986
Link To Document :
بازگشت