DocumentCode :
3282999
Title :
Content-Split Based Effective String-Matching for Multi-Core Based Intrusion Detection Systems
Author :
Subramanian, Nachiappan ; Rao, Shrisha
Author_Institution :
Centre for Dev. of Adv. Comput., Bangalore, India
fYear :
2009
fDate :
23-25 July 2009
Firstpage :
296
Lastpage :
301
Abstract :
We present a content split approach (CSA), tailored specifically for signature-based network intrusion detection. This algorithm logically partition the content of IP packets into three parts and internally uses boyer-moorehorspool algorithm to carry out string-matching simultaneously on these parts. Traditionally, skip based pattern matching algorithms use a single sliding window moving from left to right to detect a pattern to be matched, whereas CSA uses two sliding windows of the pattern simultaneously-one moving towards the right from the start position, towards the middle of the string, and the second starting from the middle and moving towards the end of the string. If both these moving patterns never find a match then CSA evaluates the middle of the string. In this paper, firstly we present our approach and experiments, secondly, we present an extension for Jumbo frames and finally, we present the application of our algorithm for multicore based intrusion detection system.
Keywords :
security of data; string matching; IP packets; Jumbo frames; boyer-moorehorspool algorithm; content-split based effective string-matching; multicore based intrusion detection systems; signature-based network intrusion detection; skip based pattern matching algorithms; sliding windows; Cities and towns; Computational intelligence; Computer networks; Information technology; Intrusion detection; Partitioning algorithms; Pattern analysis; Pattern matching; Payloads; Telecommunication traffic; Content Matching; Intrusion Detection; Multi-Core;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Computational Intelligence, Communication Systems and Networks, 2009. CICSYN '09. First International Conference on
Conference_Location :
Indore
Print_ISBN :
978-0-7695-3743-6
Type :
conf
DOI :
10.1109/CICSYN.2009.21
Filename :
5231952
Link To Document :
بازگشت