DocumentCode
449540
Title
A novel hierarchical matching algorithm for intrusion detection systems
Author
Sheu, Tzu-Fang ; Huang, Nen-Fu ; Lee, Hsiao-Ping
Author_Institution
Inst. of Commun. Eng., Nat. Tsing Hua Univ., Hsinchu, Taiwan
Volume
3
fYear
2005
fDate
28 Nov.-2 Dec. 2005
Abstract
As more and more network security threats are emerging today, the network-based intrusion detection system (NIDS) is one of the most important systems to protect the network from attacks and intrusions without modifying end-user software. Searching through entire packet headers and payloads, NIDSs can identify and classify the packets that contain malicious patterns. The most essential technology to the NIDS is an efficient multiple-pattern matching algorithm, which performs exact string matching between packets and a large set of patterns. This paper proposes a novel hierarchical multiple-pattern matching algorithm (HMA) for intrusion detection, which is a two-tier and cluster-wise matching algorithm. HMA drastically reduces the amount of external memory access as well as required memory space, enabling an efficient and cost-effective real-time IDS. The simulations show that HMA significantly improves the matching performance in both the average and the worst cases (about 1.7-63 times better than the state-of-the-art algorithms).
Keywords
computer networks; pattern matching; security of data; telecommunication security; cluster-wise matching algorithm; hierarchical multiple-pattern matching algorithm; malicious patterns; network security threats; network-based intrusion detection system; packet headers; payloads; string matching; two-tier matching algorithm; Clustering algorithms; Data security; Databases; Engines; Information security; Inspection; Intrusion detection; Pattern matching; Payloads; Protection;
fLanguage
English
Publisher
ieee
Conference_Titel
Global Telecommunications Conference, 2005. GLOBECOM '05. IEEE
Print_ISBN
0-7803-9414-3
Type
conf
DOI
10.1109/GLOCOM.2005.1577938
Filename
1577938
Link To Document