DocumentCode
3037599
Title
Distributed Data Parallel Techniques for Content-Matching Intrusion Detection Systems
Author
Kopek, Christopher V. ; Fulp, Errin W. ; Wheeler, Patrick S.
Author_Institution
Department of Computer Science, Wake Forest University, Winston-Salem, NC, 27109. Email: kopekcv@gmail.com
fYear
2007
fDate
29-31 Oct. 2007
Firstpage
1
Lastpage
7
Abstract
Content matching is a necessary component of any signature-based network Intrusion Detection System (IDS). These packet inspections typically require considerable delay often consuming more than 70% of the IDS processing time. Unfortunately, this delay becomes more significant as security policies and network speeds continue to increase. This paper introduces a new parallel IDS content matching technique that provides initial packet inspections with less delay. The technique distributes portions of a packet payload across an array of n processors, each responsible for scanning a smaller amount of original payload. Given this design, each processor has less data to inspect thus reducing the overall delay. Unlike similar parallel approaches, our technique ensures that security is maintained (no false negatives). Furthermore, the proposed parallel technique is shown to result in an initial match speed-up of approximately 1.25n using Snort (an open source IDS), actual IDS policies, and traffic traces - a significant improvement over current parallel techniques.
Keywords
Automata; Computer science; Data security; Delay effects; High-speed networks; Inspection; Intrusion detection; Next generation networking; Payloads; Process design; Aho-Corasick; Data Parallel; Intrusion Detection; Packet; Parallel; Signature Matching; Snort; Wu-Manber;
fLanguage
English
Publisher
ieee
Conference_Titel
Military Communications Conference, 2007. MILCOM 2007. IEEE
Conference_Location
Orlando, FL, USA
Print_ISBN
978-1-4244-1513-7
Electronic_ISBN
978-1-4244-1513-7
Type
conf
DOI
10.1109/MILCOM.2007.4454922
Filename
4454922
Link To Document