期刊文献+

Snort的高效规则匹配算法 被引量:16

Efficient Rule-matching Algorithms on Snort
下载PDF
导出
摘要 对入侵检测系统Snort的规则匹配算法进行了系统的分析,为了进一步提高Snort的规则匹配效率,提出了在匹配过程中,对于条件匹配处理函数应用参数链表驱动的方法。从而避免重复调用处理函数,充分利用参数之间的关系,并能动态地减少无效规则的匹配。通过两个实验来评估此方法的效率,结果表明改进方案较明显地提高了Snort的检测性能。 This paper systematically analyzes the rule matching algorithm of Snort, an open source-code NIDS. In order to increase effectively the rule matching speed, an approach of parameter-list-driven is proposed for the conditional checking subroutine during rule matching. The means can avoid repeatedly invoking the checking subroutines, can utilize relationship between parameters, and can significantly reduce invalid rules in the running time. Finally, two experiments are done for evaluating the efficiency of it. The result shows the approach can greatly improve the detecting performance of Snort.
出处 《计算机工程》 EI CAS CSCD 北大核心 2006年第18期155-156,213,共3页 Computer Engineering
关键词 基于网络的入侵检测系统 规则匹配 参数驱动 NIDS Rule matching Parameter-driven
  • 相关文献

参考文献4

  • 1Roesch M.Snort-lightweight Intrusion Detection for Networks[Z].http://www.snort.org/docs/lisapaper.txt,2003-02-20.
  • 2Roesch M,Green C.Snort Users Manual[Z].http://www.snort.org,2004-08-11.
  • 3Coit J C,Staniford S,McAlerney J.Towards Faster String Matching for Intrusion Detection[C].Proc.of DARPA Information Survivability Conference and Exposition,2001:367-373.
  • 4Norton M,Roelker D.Hi-performance Multi-rule Inspection Engine[Z].http://www.snort.org,2004-04.

同被引文献51

引证文献16

二级引证文献25

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部