摘要
网络入侵检测依赖于字符串匹配技术.尽管各种有效的字符串匹配技术不断被使用,但字符串匹配过程的消耗仍是入侵监测系统运行的主要系统开销.为了提高入侵监测系统的运行效率和运算能力,提出并设计了新的字符串匹配算法(NM SA).算法采用新的匹配思想,应用启发函数获得优于BM移动步长的新的跳跃,同时采用有限状态模式匹配自动机可同时进行多模式匹配.将算法应用于Snort系统,并和其他算法进行比较,实验证明NM SA整体上提高了系统的效率.
Intrusion Detection System (IDS) often relies on string matching techniques. String matching computations dominate the overall cost of running a IDS, despite the use of efficient general-purpose string matching algorithms. In order to increase the efficiency and capacity of IDS, a new matching string algorithm (NMSA) is designed, which applies both of a new matching idea in the heuristic function to gain longer forward step, and the finite state automaton to carry on multi-pattern matching simultaneously. Then after the implementation of NMSA in Snort, the experiments for comparing NMSA with the best alternative solution are given, which prove that NMSA offers improvements in overall system performance.
出处
《大连理工大学学报》
EI
CAS
CSCD
北大核心
2006年第4期594-601,共8页
Journal of Dalian University of Technology
基金
国家自然科学基金资助项目(70272050)~~
关键词
入侵检测
多模式匹配
NMSA
intrusion detection
multi-pattern matching
NMSA