New method of pattern-matching for network intrusion detection
FAN Ai-jing1,YANG Zhao-feng2
1. Network Computer Center, Pingdingshan University,Pingdingshan Henan 467002, China 2. School of Software Engineering, Pingdingshan University, Pingdingshan Henan 467002, China
Abstract:New generations of Network Intrusion Detection Systems (NIDS) create the need for advanced pattern-matching engines. This paper presented a new scheme for pattern-matching, which adopted a hardware-based programmable state machine technology to achieve deterministic processing rates. A lot of patterns can be obtained in one input stream by Balanced Routing Table-based FSM (B-FSM), and transition rules can be mapped effectively. Experiments had been done with Snort used widely in network intrusion detection systems. The experimental results show that the method is effective in storage, fast in operation, and renewable dynamically. The method proposed in this paper can satisfy the requirement of NIDS.
樊爱京 杨照峰. 用于网络入侵检测的模式匹配新方法[J]. 计算机应用, 2011, 31(11): 2961-2964.
FAN Ai-jing YANG Zhao-feng. New method of pattern-matching for network intrusion detection. Journal of Computer Applications, 2011, 31(11): 2961-2964.