A Fast Pattern-Match Engine for Network Processor-based Network Intrusion Detection System

  • Authors:
  • Rong-Tai Liu;Nen-Fu Huang;Chia-Nan Kao;Chih-Hao Chen;Chi-Chieh Chou

  • Affiliations:
  • -;-;-;-;-

  • Venue:
  • ITCC '04 Proceedings of the International Conference on Information Technology: Coding and Computing (ITCC'04) Volume 2 - Volume 2
  • Year:
  • 2004

Quantified Score

Hi-index 0.00

Visualization

Abstract

Network Intrusion Detection Systems (NIDS) are oneof the latest developments in security. The matching ofpacket strings against collected signatures dominatessignature-based NIDS performance. This work presentsFNP2, an efficient pattern-matching engine designed forNetwork Processor platform which conducts matchingsets of patterns in parallel. This work shows thatcombining our string matching methodology, hashingengine supported by most Network Processors, andcharacteristics of current Snort signatures frequentlyimproves performance and reduces number of memoryaccesses compared to current NIDS pattern matchingalgorithms. Another contribution is to highlight that,besides total number of searching patterns, shortestpattern length is also a major influence on NIDS multi-patternmatching algorithm performance.