{"title":"入侵检测系统中碎片和乱序包流的多模式匹配技术","authors":"Manish Kumar, M. Hanumanthappa","doi":"10.1109/ICCCNT.2013.6726491","DOIUrl":null,"url":null,"abstract":"In this paper we are discussing about Intrusion Detection System based on Deterministic Finite-State Automata (DFA). The proposed system is designed to deal the fragmented and out-of-order packets. Fragmentation is the term given to the process of breaking down an IP datagram into smaller packets to be transmitted over different types of network media and then reassembling them at the other end. In most cases, depending upon the actual security device defending the network, there are typically multiple fragmentation techniques and packet size combinations capable of squeezing and exploiting protection device on a network. We present an efficient multi pattern algorithm for regular expression matching on streams with fragmented and out of order data, while maintaining a small state and without complete stream reconstruction. It improves the performance of Intrusion Detection System for detecting the fragmented and Out-of-Order packet attack. The proposed technique helps to achieve high throughput while limiting both memory-usage and memory-bandwidth on fragmented data packets intrusion.","PeriodicalId":6330,"journal":{"name":"2013 Fourth International Conference on Computing, Communications and Networking Technologies (ICCCNT)","volume":"5 1","pages":"1-6"},"PeriodicalIF":0.0000,"publicationDate":"2013-07-04","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":"{\"title\":\"Multi pattern matching technique on fragmented and out-of-order packet streams for intrusion detection system\",\"authors\":\"Manish Kumar, M. Hanumanthappa\",\"doi\":\"10.1109/ICCCNT.2013.6726491\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"In this paper we are discussing about Intrusion Detection System based on Deterministic Finite-State Automata (DFA). The proposed system is designed to deal the fragmented and out-of-order packets. Fragmentation is the term given to the process of breaking down an IP datagram into smaller packets to be transmitted over different types of network media and then reassembling them at the other end. In most cases, depending upon the actual security device defending the network, there are typically multiple fragmentation techniques and packet size combinations capable of squeezing and exploiting protection device on a network. We present an efficient multi pattern algorithm for regular expression matching on streams with fragmented and out of order data, while maintaining a small state and without complete stream reconstruction. It improves the performance of Intrusion Detection System for detecting the fragmented and Out-of-Order packet attack. The proposed technique helps to achieve high throughput while limiting both memory-usage and memory-bandwidth on fragmented data packets intrusion.\",\"PeriodicalId\":6330,\"journal\":{\"name\":\"2013 Fourth International Conference on Computing, Communications and Networking Technologies (ICCCNT)\",\"volume\":\"5 1\",\"pages\":\"1-6\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2013-07-04\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2013 Fourth International Conference on Computing, Communications and Networking Technologies (ICCCNT)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/ICCCNT.2013.6726491\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2013 Fourth International Conference on Computing, Communications and Networking Technologies (ICCCNT)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICCCNT.2013.6726491","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
Multi pattern matching technique on fragmented and out-of-order packet streams for intrusion detection system
In this paper we are discussing about Intrusion Detection System based on Deterministic Finite-State Automata (DFA). The proposed system is designed to deal the fragmented and out-of-order packets. Fragmentation is the term given to the process of breaking down an IP datagram into smaller packets to be transmitted over different types of network media and then reassembling them at the other end. In most cases, depending upon the actual security device defending the network, there are typically multiple fragmentation techniques and packet size combinations capable of squeezing and exploiting protection device on a network. We present an efficient multi pattern algorithm for regular expression matching on streams with fragmented and out of order data, while maintaining a small state and without complete stream reconstruction. It improves the performance of Intrusion Detection System for detecting the fragmented and Out-of-Order packet attack. The proposed technique helps to achieve high throughput while limiting both memory-usage and memory-bandwidth on fragmented data packets intrusion.