DocumentCode :
2418067
Title :
An Approach for Unifying Rule Based Deep Packet Inspection
Author :
Munoz, A. ; Sezer, S. ; Burns, D. ; Douglas, G.
Author_Institution :
Centre for Secure Inf. Technol. (CSIT), Queen´´s Univ. of Belfast, Belfast, UK
fYear :
2011
fDate :
5-9 June 2011
Firstpage :
1
Lastpage :
5
Abstract :
High performance Internet traffic inspection and layer-7 content analysis have become essential functions of high speed networks. Over the past decade several DPI systems have evolved targeting specific issues related to traffic management, user/application policing, intrusion detection/prevention, URL/malicious/unwanted content filtering. Snort, OpenDPI, Bro, L7-filter, ClamAV are a number of open-source tools based on custom DPI engines and custom rule-sets. The surging demand for higher bandwidth DPI systems capable of supporting larger rule-sets requires the use of hardware acceleration and hardware-based systems. In comparison to software based systems, the design and development of custom purpose hardware for DPI is expensive. The need for DPI solutions for a range of applications at high speed requires a unified processing platform. This paper presents the research in converting known DPI rule-sets into a meta format based on regular expressions, that can be executed by software and hardware-based processing platforms. To demonstrate this work a Snort2Regex translator has been developed to transform Snort rules into regular expressions using not only the content of the Snort rule but every relevant element that belongs to it and could increase the accuracy of the analysis.
Keywords :
Internet; computer network management; computer network security; inspection; public domain software; telecommunication traffic; Bro; ClamAV; Internet traffic inspection; L7-filter; OpenDPI; Snort2Regex translator; URL content filtering; application policing; hardware acceleration; hardware-based processing platform; hardware-based system; high speed network; intrusion detection; intrusion prevention; layer-7 content analysis; malicious content filtering; meta format; open-source tools; rule based deep packet inspection; software-based processing platform; traffic management; unwanted content filtering; user policing; Hardware; IP networks; Internet; Intrusion detection; Payloads; Protocols; Syntactics;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Communications (ICC), 2011 IEEE International Conference on
Conference_Location :
Kyoto
ISSN :
1550-3607
Print_ISBN :
978-1-61284-232-5
Electronic_ISBN :
1550-3607
Type :
conf
DOI :
10.1109/icc.2011.5963095
Filename :
5963095
Link To Document :
بازگشت