High-Performance Pattern-Matching for Intrusion Detection
High-Performance Pattern-Matching for Intrusion Detection
复制标题
DOI:
10.1109/infocom.2006.204
复制
发表时间:
2006-04
期刊:
影响因子:
--
通讯作者:
J. V. Lunteren
中科院分区:
文献类型:
--
作者:
J. V. Lunteren
New generations of network intrusion detection systems create the need for advanced pattern-matching engines. This paper presents a novel scheme for pattern-matching, called BFPM, that exploits a hardware-based programmable statemachine technology to achieve deterministic processing rates that are independent of input and pattern characteristics on the order of 10 Gb/s for FPGA and at least 20 Gb/s for ASIC implementations. BFPM supports dynamic updates and is one of the most storage-efficient schemes in the industry, supporting two thousand patterns extracted from Snort with a total of 32 K characters in only 128 KB of memory.