Title :
A fast pattern matching algorithm for network processor-based intrusion detection system
Author :
Liu, Rong-Tai ; Huang, Nen-Fu ; Kao, Chia-Nan ; Chen, Chih-Hao
Author_Institution :
Dept. of Comput. Sci., Nat. Tsing Hua Univ., Taiwan
Abstract :
Network intrusion detection systems (NIDS) monitor packets on the network and attempts to discover if a hacker is attempting to break into a system. The matching of packet strings against collected signatures dominates signature-based NIDS performance. Network processors are one of the fastest growing segments of the semiconductor market, because they are designed to provide scalable and flexible solutions that can accommodate change quickly and economically. This work presents a fast string matching algorithm (called FNP) over the network processor platform that conducts matching sets of patterns in parallel. FNP needs less number of memory accesses against conventional pattern-matching algorithms. Another contribution of this work is to highlight that, besides total number of searching patterns, shortest pattern length is also a major influence on NIDS multi-pattern matching algorithm performance.
Keywords :
computer networks; safety systems; string matching; telecommunication security; fast string matching algorithm; memory accesses; multipattern matching algorithm; network intrusion detection systems; network processor; Automation; Change detection algorithms; Computer displays; Computer hacking; Computer networks; Computer science; Intrusion detection; Manufacturing; Open source software; Pattern matching;
Conference_Titel :
Performance, Computing, and Communications, 2004 IEEE International Conference on
Print_ISBN :
0-7803-8396-6
DOI :
10.1109/PCCC.2004.1394999