Title :
Towards faster string matching for intrusion detection or exceeding the speed of Snort
Author :
Coit, C.J. ; Staniford, Stuart ; McAlerney, J.
Abstract :
Network intrusion detection systems (NIDS) often rely on exact string matching techniques. Depending on the choice of algorithm, implementation and the frequency with which it is applied, this pattern matching may become a performance bottleneck. To keep up with increasing network speeds and traffic, NIDS can take advantage of advanced string matching algorithms. We describe the effectiveness of a significantly faster approach to pattern matching in the open source NIDS Snort
Keywords :
computer network management; security of data; string matching; Snort; advanced string matching algorithms; exact string matching techniques; network intrusion detection systems; pattern matching; Frequency; Intrusion detection; Monitoring; Pattern analysis; Pattern matching; Performance analysis; Protocols; Silicon; Telecommunication traffic; Web server;
Conference_Titel :
DARPA Information Survivability Conference & Exposition II, 2001. DISCEX '01. Proceedings
Conference_Location :
Anaheim, CA
Print_ISBN :
0-7695-1212-7
DOI :
10.1109/DISCEX.2001.932231