Hashing + memory = low cost, exact pattern matching

Hashing + memory = low cost, exact pattern matching
复制标题

DOI:
10.1109/fpl.2005.1515696
复制
发表时间:
2005-10
期刊:
International Conference on Field Programmable Logic and Applications, 2005.
影响因子:
--
通讯作者:
G. Papadopoulos;D. Pnevmatikatos
G. Papadopoulos;D. Pnevmatikatos
中科院分区:
其他
文献类型:
--
作者:
G. Papadopoulos;D. Pnevmatikatos

文献摘要

被引文献

相似文献

在本文中,我们提出了哈希和使用记忆的结合,以实现低成本,完全匹配类似Snort的入侵签名。基本思想是使用哈希为每个候选模式生成一个独特的地址,该地址存储在内存中。我们的实现Hash-Mem使用了用XOR门实现的简单CRC风格的多项式来实现输入模式的低成本哈希。我们使用间接存储器来降低内存的稀疏度,该内部存储器允许搜索模式的紧凑型存储,并使用简单的比较器验证匹配器。我们的实现用每个搜索模式字符的0.15逻辑单元格和几十个内存块的使用顺序使用,在中小型FPGA设备中舒适地拟合。
In this paper we propose the combination of hashing and use of memory to achieve low cost, exact matching of SNORT-like intrusion signatures. The basic idea is to use hashing to generate a distinct address for each candidate pattern, which is stored in memory. Our implementation, hash-mem, uses simple CRC-style polynomials implemented with XOR gates, to achieve low cost hashing of the input patterns. We reduce the sparseness of the memory using an indirection memory that allows a compact storing of the search patterns and use a simple comparator to verify the match. Our implementation uses in the order of 0.15 logic cells per search pattern character, and a few tens of memory blocks, fitting comfortably in small or medium FPGA devices.