Hashing + memory = low cost, exact pattern matching
Hashing + memory = low cost, exact pattern matching
复制标题
DOI:
10.1109/fpl.2005.1515696
复制
发表时间:
2005-10
期刊:
影响因子:
--
通讯作者:
G. Papadopoulos;D. Pnevmatikatos
中科院分区:
文献类型:
--
作者:
G. Papadopoulos;D. Pnevmatikatos
In this paper we propose the combination of hashing and use of memory to achieve low cost, exact matching of SNORT-like intrusion signatures. The basic idea is to use hashing to generate a distinct address for each candidate pattern, which is stored in memory. Our implementation, hash-mem, uses simple CRC-style polynomials implemented with XOR gates, to achieve low cost hashing of the input patterns. We reduce the sparseness of the memory using an indirection memory that allows a compact storing of the search patterns and use a simple comparator to verify the match. Our implementation uses in the order of 0.15 logic cells per search pattern character, and a few tens of memory blocks, fitting comfortably in small or medium FPGA devices.