跳至主導覽 跳至搜尋 跳過主要內容

Two-phase pattern matching for regular expressions in intrusion detection systems

  • Chang Ching Yang*
  • , Chen Mou Cheng
  • , Sheng D.E. Wang
  • *此作品的通信作者
  • National Taiwan University

研究成果: 期刊稿件文章同行評審

3 引文 斯高帕斯(Scopus)

摘要

Regular expressions are used to describe security threats' signatures in network intrusion detection (NID) systems. To identify suspicious packets using regular expression matching, many NID systems use memory-based deterministic finite-state automata (DFA) with one-pass-scanning model, which is fast and allows dynamic updates. However, a number of practical signature patterns commonly found in a variety of NID systems, e.g., ". *A. {N}B", can cause a state-explosion problem in such a model. In this paper, we propose a two-phase pattern matching engine (TPME) to solve this problem. In our proposed approach, the state storage cost is reduced to linearly dependent on the number of repetitions N in the patterns. With the new approach, we are now able to handle those practical patterns that would have caused the state-explosion problem in memory-based DFA. We report our implementation of TPME on a field programmable gate array (FPGA). With our prototype implementation, we can achieve a throughput of more than 1.86 gigabits per second for pattern matching in a practical NID system.

原文英語
頁(從 - 到)1563-1582
頁數20
期刊Journal of Information Science and Engineering
26
發行號5
出版狀態已出版 - 09 2010
對外發佈

指紋

深入研究「Two-phase pattern matching for regular expressions in intrusion detection systems」主題。共同形成了獨特的指紋。

引用此