Smart architecture for high-speed intrusion detection and prevention systems

  • Authors:
  • Chih-Chiang Wu;Sung-Hua Wen;Nen-Fu Huang

  • Affiliations:
  • Computer and Communication Research Center (CCRC), National Tsing Hua University, Taiwan;Institute of Communication Engineering, National Tsing Hua University, Taiwan;Institute of Communication Engineering, National Tsing Hua University, Taiwan

  • Venue:
  • CANS'06 Proceedings of the 5th international conference on Cryptology and Network Security
  • Year:
  • 2006

Quantified Score

Hi-index 0.00

Visualization

Abstract

The overall performance of an intrusion protection system depends not only on the packet header classification and pattern matching, but also on the post-operative determination of correlative patterns of matched rules. An increasing number of patterns associated with a rule heighten the importance of correlative pattern matching. This work proposes a TCAM-based smart architecture that supports both deep pattern-matching and correlative pattern-matching. The proposed architecture overcomes the difficulties in implementing TCAM when the patterns are very deep and the rules for packet payload involve many patterns whose positions lie within a range. A real case payload is simulated using a Snort 2.3 rule set and simulation results demonstrate the feasibility of the proposed architecture in supporting a high-speed and robust intrusion detection and prevention system.