期刊文献+

IDS中新的快速多模式匹配算法及其设计(英文) 被引量:1

A new faster multi-pattern matching algorithm and design in IDS
下载PDF
导出
摘要 网络入侵检测依赖于字符串匹配技术.尽管各种有效的字符串匹配技术不断被使用,但字符串匹配过程的消耗仍是入侵监测系统运行的主要系统开销.为了提高入侵监测系统的运行效率和运算能力,提出并设计了新的字符串匹配算法(NM SA).算法采用新的匹配思想,应用启发函数获得优于BM移动步长的新的跳跃,同时采用有限状态模式匹配自动机可同时进行多模式匹配.将算法应用于Snort系统,并和其他算法进行比较,实验证明NM SA整体上提高了系统的效率. Intrusion Detection System (IDS) often relies on string matching techniques. String matching computations dominate the overall cost of running a IDS, despite the use of efficient general-purpose string matching algorithms. In order to increase the efficiency and capacity of IDS, a new matching string algorithm (NMSA) is designed, which applies both of a new matching idea in the heuristic function to gain longer forward step, and the finite state automaton to carry on multi-pattern matching simultaneously. Then after the implementation of NMSA in Snort, the experiments for comparing NMSA with the best alternative solution are given, which prove that NMSA offers improvements in overall system performance.
出处 《大连理工大学学报》 EI CAS CSCD 北大核心 2006年第4期594-601,共8页 Journal of Dalian University of Technology
基金 国家自然科学基金资助项目(70272050)~~
关键词 入侵检测 多模式匹配 NMSA intrusion detection multi-pattern matching NMSA
  • 相关文献

参考文献17

  • 1DESAI N. Increasing performance in high speed at snort's Internals IDS [EB/OL]. [2002-08-01].http : //www. securitywizards. com
  • 2BOYER R S, MOORE J S. A fast string searching algorithm [J]. Commun of the ACM, 1997,20: 762-772
  • 3FISK M, VARGHESE G. Fast content-based packet handling for intrusion detection: UCSD Technical Report [R]. USA:UCSD, 2001
  • 4CHARRAS C, LECROA T. Boyer-Moore algorithm [EB/OL]. [1994-01-14]. http: //www. snort. org/
  • 5ROESCH M. Snort - lightweight intrusion detection for networks [C] // USENIX LISA Conference. Seattle: [s n], 1999
  • 6AHO A, CORASICK M. Efficient string matchingan aid to bibliographic search [J]. Commun of the ACM, 1975, 18:333-340
  • 7SUN Wu, MANBER U. A fast algorithm for multi-pattern searching: Tech. Rep. TR94-17[R]. Arizona : Department of Computer Science, University of Arizona, 1994
  • 8KIM S, KIM Y G. A fast multiple string-pattern matching algorithm [C] // Proceedings of the 17th AoM/IAoM Inernational Conference on Computer Science. San Diego: [s n], 1999
  • 9COIT C J, STANIFORD S. Toward faster string matching for intrusion detection or exceeding the speed of snort [C] // Proceedings of 2nd DARPA Information Survivability Conference and Exposition (DISCEX Ⅱ). Piscataway: IEEE CS Press, 2001: 367-373
  • 10MICHAEL C, GHOSH A. Using finite automate to mine execution data for intrusion detection: A Preliminary Report, Lecture Notes in Computer Science (1907)[R]. [s l]: RAID, 2000

同被引文献4

引证文献1

二级引证文献1

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部