• DocumentCode
    3264873
  • Title

    Adaptive Character Frequency-Based Exclusive Signature Matching Scheme in Distributed Intrusion Detection Environment

  • Author

    Meng, Yuxin ; Li, Wenjuan

  • Author_Institution
    Dept. of Comput. Sci., City Univ. of Hong Kong, Hong Kong, China
  • fYear
    2012
  • fDate
    25-27 June 2012
  • Firstpage
    223
  • Lastpage
    230
  • Abstract
    Currently, signature-based network intrusion detection systems (NIDSs) are being widely deployed in distributed network environment with the purpose of protecting network communications from various attacks. However, signature matching has become a key limiting factor to restrict the performance of a signature-based NIDS in large-scale distributed network environment. The overhead network packets can greatly reduce the effectiveness of such detection systems and heavily consume computer resources. To mitigate this issue, a more efficient signature matching algorithm is desirable. In this paper, we therefore develop an adaptive character frequency-based exclusive signature matching scheme that can be implemented in a signature-based NIDS to help improve the performance of signature matching. In the experiment, we implemented our scheme in a distributed network environment and evaluated the performance of our scheme compared with Snort. The experimental results show that, in our distributed network environment, our scheme can positively reduce the time consumption in the range from 11.2% to 37.6%.
  • Keywords
    computer network performance evaluation; computer network security; digital signatures; distributed processing; pattern matching; adaptive character frequency-based exclusive signature matching scheme; distributed intrusion detection environment; key limiting factor; network communication protection; overhead network packets; performance evaluation; signature-based NIDS; signature-based network intrusion detection systems; Adaptive systems; Algorithm design and analysis; Intrusion detection; Pattern matching; Payloads; Servers; Exclusive signature matching; Intrusion detection; Network security and performance;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Trust, Security and Privacy in Computing and Communications (TrustCom), 2012 IEEE 11th International Conference on
  • Conference_Location
    Liverpool
  • Print_ISBN
    978-1-4673-2172-3
  • Type

    conf

  • DOI
    10.1109/TrustCom.2012.65
  • Filename
    6295979