Scalable packet classification for network intrusion detection

  • Authors:
  • Pi-Chung Wang;Chia-Ming Chang

  • Affiliations:
  • National Chung Hsing University, Taichung, Taiwan, R.O.C.;National Taiwan University, Taipei, Taiwan, R.O.C.

  • Venue:
  • CSS '07 Proceedings of the Fifth IASTED International Conference on Circuits, Signals and Systems
  • Year:
  • 2007

Quantified Score

Hi-index 0.00

Visualization

Abstract

Network intrusion detection systems, which protect high-speed networks, demand both high throughput and scalability to handle new threats. In this paper, we propose a scalable algorithm of multimatch packet classification for network intrusion detection to handle the potentially increasing filters resulted from new threats. The algorithm utilizes the previous idea, which categorizes filters based on distinct length combinations and corresponds each combination to one hash table. The classification procedure consists of d one-dimensional lookups and T hash accesses. We adopt ternary content addressable memory (TCAM) to accomplish the one-dimensional lookups. As compared to the existing schemes, the proposed scheme shows a better leverage between speed and storage performance.