• DocumentCode
    3216282
  • Title

    Improved TCAM-Based Pre-Filtering for Network Intrusion Detection Systems

  • Author

    Chang, Yeim-Kuan ; Tsai, Ming-Li ; Su, Cheng-Chien

  • Author_Institution
    Nat. Cheng Kung Univ., Tainan
  • fYear
    2008
  • fDate
    25-28 March 2008
  • Firstpage
    985
  • Lastpage
    990
  • Abstract
    With the increasing growth of the Internet, the explosion of attacks and viruses significantly affects the network security. Network intrusion detection system (NIDS) is developed to identify these network attacks by a set of rules. However, searching for multiple patterns is a computationally expensive task in NIDS. Traditional software-based solutions can not meet the high bandwidth demanded in current high-speed networks. In the past, the pre-filtering designed for NIDS is an effective technique that can reduce the processing overhead significantly. A FNP- like TCAM searching engine (FTSE) is an example that uses an 2-stage architecture to detect whether an incoming string contains patterns. In this paper, we propose two techniques to improve the performance of FTSE that utilizes ternary content addressable memory (TCAM) as pre-filter to achieve gigabit performance. The first technique performs the w-byte suffix pattern match instead of using w-byte prefix. The second technique finds the matching results from all groups rather than first group. We finally present the simulation result using Snort pattern set and DEFCON packet traces.
  • Keywords
    Internet; information filtering; security of data; FTSE; Internet; TCAM-based pre-filtering; network intrusion detection systems; ternary content addressable memory; w-byte prefix; w-byte suffix pattern match; Bandwidth; Computer viruses; Databases; Filters; High-speed networks; IP networks; Intrusion detection; Pattern matching; Protection; Viruses (medical); TCAM; network intrusion detection;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Advanced Information Networking and Applications, 2008. AINA 2008. 22nd International Conference on
  • Conference_Location
    Okinawa
  • ISSN
    1550-445X
  • Print_ISBN
    978-0-7695-3095-6
  • Type

    conf

  • DOI
    10.1109/AINA.2008.120
  • Filename
    4482813