DocumentCode
3523114
Title
A multiple regular expressions matching architecture for network intrusion detection system
Author
Zhang, Wei ; Song, Tian ; Wang, Dongsheng
Author_Institution
Dept. of Comput. Sci. & Tech., Tsinghua Univ., Beijing
fYear
2008
fDate
25-27 Aug. 2008
Firstpage
687
Lastpage
691
Abstract
Regular expressions are increasingly used in network security applications. Multiple regular expressions matching is one of the most important performance bottlenecks in those systems. This paper proposes a new hardware-based multiple regular-expressions matching architecture, called MRM, for network intrusion detection system. It shows that traditional algorithm, such as AC, has to face the serious spatial explosion problem when simultaneously detecting a large number of regular expressions because of constrained repetitions. MRM utilizes hardware RAM modules to share matching signals and exploits hardware register counting to implement constrained repetitions. This paper also proposes a software compiler to construct the hardware architecture and generate information in MRM´s RAMs for the given regular expressions. Experiments in actual snort and bro regular expression sets show that MRM can achieve the high throughput of 2.1 Gbps and 2.8 Gbps on Virtex2 and Virtex4 devices respectively.
Keywords
packet radio networks; pattern matching; random-access storage; safety systems; security of data; telecommunication security; RAM modules; bit rate 2.1 Gbit/s; bit rate 2.8 Gbit/s; multiple regular-expressions matching; network intrusion detection system; network security; regular expressions; Automata; Computer architecture; Doped fiber amplifiers; Face detection; Hardware; Information security; Inspection; Intrusion detection; Pattern matching; Payloads; intrusion detection; pattern matching; regular expression matching;
fLanguage
English
Publisher
ieee
Conference_Titel
Communications and Networking in China, 2008. ChinaCom 2008. Third International Conference on
Conference_Location
Hangzhou
Print_ISBN
978-1-4244-2373-6
Electronic_ISBN
978-1-4244-2374-3
Type
conf
DOI
10.1109/CHINACOM.2008.4685118
Filename
4685118
Link To Document