一种改进的内容匹配入侵检测系统技术

Yanguo Wang, H. Kobayashi
{"title":"一种改进的内容匹配入侵检测系统技术","authors":"Yanguo Wang, H. Kobayashi","doi":"10.1109/SOFTCOM.2006.329755","DOIUrl":null,"url":null,"abstract":"Pattern matching is a comprehensive applicable key technology, which can be used in network security applications such as intrusion detection systems (IDS), firewall, virus detection, etc. Depending on the choice of algorithm, implementation, and the frequency to which it is applied, the pattern matching may become a performance bottleneck due to the increasing network speed and traffic. Therefore, it is very necessary to develop faster and more efficient pattern matching algorithms in order to overcome the troubles on performance. In this paper, we presented a new pattern matching algorithm based on Boyer-Moore algorithm. The improved algorithm and its working process are described in detail. Together with a new concept of reference point, a two-dimensional array NEXT redesigned based on novel generated rules in the pre-processing phase, endorse the algorithm a better performance and more efficient. The algorithm also passed tests and is validated. Our experimental results, two diverse sets of pattern strings tested on two example texts, indicate that this algorithm can enhance the average performance up to 25% ~ 44% compared to Boyer-Moore-Horspool algorithm","PeriodicalId":292242,"journal":{"name":"2006 International Conference on Software in Telecommunications and Computer Networks","volume":"15 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2006-09-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"4","resultStr":"{\"title\":\"An Improved Technology for Content Matching Intrusion Detection System\",\"authors\":\"Yanguo Wang, H. Kobayashi\",\"doi\":\"10.1109/SOFTCOM.2006.329755\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Pattern matching is a comprehensive applicable key technology, which can be used in network security applications such as intrusion detection systems (IDS), firewall, virus detection, etc. Depending on the choice of algorithm, implementation, and the frequency to which it is applied, the pattern matching may become a performance bottleneck due to the increasing network speed and traffic. Therefore, it is very necessary to develop faster and more efficient pattern matching algorithms in order to overcome the troubles on performance. In this paper, we presented a new pattern matching algorithm based on Boyer-Moore algorithm. The improved algorithm and its working process are described in detail. Together with a new concept of reference point, a two-dimensional array NEXT redesigned based on novel generated rules in the pre-processing phase, endorse the algorithm a better performance and more efficient. The algorithm also passed tests and is validated. Our experimental results, two diverse sets of pattern strings tested on two example texts, indicate that this algorithm can enhance the average performance up to 25% ~ 44% compared to Boyer-Moore-Horspool algorithm\",\"PeriodicalId\":292242,\"journal\":{\"name\":\"2006 International Conference on Software in Telecommunications and Computer Networks\",\"volume\":\"15 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2006-09-01\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"4\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2006 International Conference on Software in Telecommunications and Computer Networks\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/SOFTCOM.2006.329755\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2006 International Conference on Software in Telecommunications and Computer Networks","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/SOFTCOM.2006.329755","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 4

摘要

模式匹配是一项综合适用的关键技术,可用于入侵检测系统(IDS)、防火墙、病毒检测等网络安全应用。根据算法的选择、实现和应用频率的不同,模式匹配可能会由于网络速度和流量的增加而成为性能瓶颈。因此,开发更快、更高效的模式匹配算法以克服模式匹配在性能上的困扰是十分必要的。本文提出了一种新的基于Boyer-Moore算法的模式匹配算法。详细介绍了改进算法及其工作过程。结合新的参考点概念,在预处理阶段根据新生成的规则重新设计二维数组NEXT,使算法具有更好的性能和更高的效率。该算法通过了测试并得到了验证。实验结果表明,该算法与Boyer-Moore-Horspool算法相比,平均性能提高了25% ~ 44%
本文章由计算机程序翻译,如有差异,请以英文原文为准。
An Improved Technology for Content Matching Intrusion Detection System
Pattern matching is a comprehensive applicable key technology, which can be used in network security applications such as intrusion detection systems (IDS), firewall, virus detection, etc. Depending on the choice of algorithm, implementation, and the frequency to which it is applied, the pattern matching may become a performance bottleneck due to the increasing network speed and traffic. Therefore, it is very necessary to develop faster and more efficient pattern matching algorithms in order to overcome the troubles on performance. In this paper, we presented a new pattern matching algorithm based on Boyer-Moore algorithm. The improved algorithm and its working process are described in detail. Together with a new concept of reference point, a two-dimensional array NEXT redesigned based on novel generated rules in the pre-processing phase, endorse the algorithm a better performance and more efficient. The algorithm also passed tests and is validated. Our experimental results, two diverse sets of pattern strings tested on two example texts, indicate that this algorithm can enhance the average performance up to 25% ~ 44% compared to Boyer-Moore-Horspool algorithm
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信