摘要
随着网络速度和入侵检测规则的持续增长,模式匹配正在成为网络入侵检测系统的性能瓶颈。提出了一种新的Wu-Manber类型的模式匹配算法,通过将模式分组,对不同予模式组采用不同匹配方法,显著提高了模式匹配的效率。对比实验表明,当模式组中含有长度小于3的模式时,新算法性能比原算法平均提高了29%-44%。
With network speed and the number of rules constantly increasing, pattern matching is becoming the bottleneck in Network Intrusion Detection System ( NIDS), This paper proposed a fast Wu-Manber-like multi-pattern matching algorithm for intrusion detection, called FWM. By subdividing the pattern group into two subgroups and dealing with the two subgroups in different methods, the FWM algorithm enhanced the efficiency of pattern matching. Experimental results show that, when pattern group contains the pattern that is less than three bytes, the FWM algorithm improves average performance by 29% - 44% compared to the original NIDS pattern matching algorithm.
出处
《计算机应用》
CSCD
北大核心
2008年第1期82-84,共3页
journal of Computer Applications
基金
广西自然科学基金资助项目(0728099)