High-Performance Pattern-Matching for Intrusion Detection

High-Performance Pattern-Matching for Intrusion Detection
复制标题

DOI:
10.1109/infocom.2006.204
复制
发表时间:
2006-04
期刊:
Proceedings IEEE INFOCOM 2006. 25TH IEEE International Conference on Computer Communications
影响因子:
--
通讯作者:
J. V. Lunteren
J. V. Lunteren
中科院分区:
其他
文献类型:
--
作者:
J. V. Lunteren

文献摘要

被引文献

相似文献

新一代的网络入侵检测系统创造了对高级模式匹配引擎的需求。本文提出了一种新颖的图案匹配方案,称为BFPM,该方案利用了基于硬件的可编程statemachine技术来实现确定性处理率,该速率独立于输入和模式特征,即FPGA的10 GB/s顺序,至少为20 GB/S用于ASIC实施。 BFPM支持动态更新,并且是行业中最具存储效率的方案之一,支持从Snort中提取的两千种模式,总共只有128 kb的内存,总共有32 K个字符。
New generations of network intrusion detection systems create the need for advanced pattern-matching engines. This paper presents a novel scheme for pattern-matching, called BFPM, that exploits a hardware-based programmable statemachine technology to achieve deterministic processing rates that are independent of input and pattern characteristics on the order of 10 Gb/s for FPGA and at least 20 Gb/s for ASIC implementations. BFPM supports dynamic updates and is one of the most storage-efficient schemes in the industry, supporting two thousand patterns extracted from Snort with a total of 32 K characters in only 128 KB of memory.