• DocumentCode
    3037599
  • Title

    Distributed Data Parallel Techniques for Content-Matching Intrusion Detection Systems

  • Author

    Kopek, Christopher V. ; Fulp, Errin W. ; Wheeler, Patrick S.

  • Author_Institution
    Department of Computer Science, Wake Forest University, Winston-Salem, NC, 27109. Email: kopekcv@gmail.com
  • fYear
    2007
  • fDate
    29-31 Oct. 2007
  • Firstpage
    1
  • Lastpage
    7
  • Abstract
    Content matching is a necessary component of any signature-based network Intrusion Detection System (IDS). These packet inspections typically require considerable delay often consuming more than 70% of the IDS processing time. Unfortunately, this delay becomes more significant as security policies and network speeds continue to increase. This paper introduces a new parallel IDS content matching technique that provides initial packet inspections with less delay. The technique distributes portions of a packet payload across an array of n processors, each responsible for scanning a smaller amount of original payload. Given this design, each processor has less data to inspect thus reducing the overall delay. Unlike similar parallel approaches, our technique ensures that security is maintained (no false negatives). Furthermore, the proposed parallel technique is shown to result in an initial match speed-up of approximately 1.25n using Snort (an open source IDS), actual IDS policies, and traffic traces - a significant improvement over current parallel techniques.
  • Keywords
    Automata; Computer science; Data security; Delay effects; High-speed networks; Inspection; Intrusion detection; Next generation networking; Payloads; Process design; Aho-Corasick; Data Parallel; Intrusion Detection; Packet; Parallel; Signature Matching; Snort; Wu-Manber;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Military Communications Conference, 2007. MILCOM 2007. IEEE
  • Conference_Location
    Orlando, FL, USA
  • Print_ISBN
    978-1-4244-1513-7
  • Electronic_ISBN
    978-1-4244-1513-7
  • Type

    conf

  • DOI
    10.1109/MILCOM.2007.4454922
  • Filename
    4454922