High Speed Pattern Matching for Network IDS/IPS

High Speed Pattern Matching for Network IDS/IPS
复制标题

DOI:
10.1109/icnp.2006.320212
复制
发表时间:
2006-11
期刊:
Proceedings of the 2006 IEEE International Conference on Network Protocols
影响因子:
--
通讯作者:
M. Alicherry;M. Muthuprasanna;Vijay P. Kumar
M. Alicherry;M. Muthuprasanna;Vijay P. Kumar
中科院分区:
其他
文献类型:
--
作者:
M. Alicherry;M. Muthuprasanna;Vijay P. Kumar

文献摘要

被引文献

相似文献

在过去十年中,互联网的惊人增长以及社会对其越来越多的依赖,对网络和计算基础架构的安全攻击泛滥。入侵检测/预防系统通过监视标头和流过网络的数据包的有效载荷提供防御这些攻击的防御。可以同时比较数百个字符串模式的多个字符串匹配是这些系统的关键组成部分,并且是一个充分的问题。当今的大多数弦匹配解决方案都是基于经典的Aho-Corasick算法,该算法具有固有的限制。他们只能在一个周期中处理一个输入字符。由于内存速度的增长与网络速度的速度不同,因此这种限制已成为当前网络中的瓶颈,每秒具有数十千兆位的速度。在本文中,我们提出了一种新颖的多种字符串匹配算法,该算法可以一次处理多个字符,从而达到多gabit速率搜索速度。我们还为基于TCAM的硬件进行有效实现提供了一个体系结构。我们还通过利用TCAM的特性来显着减少所提出算法的记忆要求,从而提出新的优化。我们最终使用实际签名数据库对基于网络的病毒/蠕虫检测进行了广泛的模拟结果,以说明所提出的方案的有效性。
The phenomenal growth of the Internet in the last decade and society's increasing dependence on it has brought along, a flood of security attacks on the networking and computing infrastructure. Intrusion detection/prevention systems provide defenses against these attacks by monitoring headers and payload of packets flowing through the network. Multiple string matching that can compare hundreds of string patterns simultaneously is a critical component of these systems, and is a well-studied problem. Most of the string matching solutions today are based on the classic Aho-Corasick algorithm, which has an inherent limitation; they can process only one input character in one cycle. As memory speed is not growing at the same pace as network speed, this limitation has become a bottleneck in the current network, having speeds of tens of gigabits per second. In this paper, we propose a novel multiple string matching algorithm that can process multiple characters at a time thus achieving multi-gigabit rate search speeds. We also propose an architecture for an efficient implementation on TCAM-based hardware. We additionally propose novel optimizations by making use of the properties of TCAMs to significantly reduce the memory requirements of the proposed algorithm. We finally present extensive simulation results of network-based virus/worm detection using real signature databases to illustrate the effectiveness of the proposed scheme.