arrow
Return

A Memory-Efficient Parallel String Matching for Intrusion Detection Systems

delete2009-12-01
delete14
PRE
AI
H
Hyunjin Kim *
H
Hyejeong Hong
H
Hong‐Sik Kim
S
Sungho Kang
DOI:10.1109/LCOMM.2009.12.082230delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
As the variety of hazardous packet payload contents increases, the intrusion detection system (IDS) should he able to detect numerous patterns in real time. For this reason, this paper proposes an Aho-Corasick algorithm based parallel string matching. In order to balance memory usage between homogeneous finite-state machine (FSM) tiles for each string matcher, an optimal set of bit position groups is determined. Target patterns are sorted by binary-reflected gray code (BRGC), which reduces bit transitions in patterns mapped onto a string matcher. In the evaluations of Snort rules, the proposed string matching outperforms the existing bit-split string matching.
Keywords:
Computer network security
finite state machines
site security monitoring
string matching

Journal

IEEE Communications Letters cover
IEEE Communications Letters
IF:
4.4
Papers:
1.3W
Citations:
2.2W

Organization

Y
Yonsei University
Scholars:
4.8W
Papers: 4.6W
Citations: 5.2W