Using Cell Processors for Intrusion Detection through Regular Expression Matching with Speculation

Complex, Intelligent and Software Intensive Systems(2011)

引用 2|浏览3
暂无评分
摘要
The main purpose of network intrusion detection systems is to determine whether incoming network traffic matches known attack signatures. To achieve this goal each of the stored signatures represents a description of an attack or an undesired event in the monitored network. The main weakness with existing signature matching algorithms is that they are essentially serial operations and it is hard for them to keep up with the growing network speed. The major bottleneck in intrusion detection systems is that they are able to scan only one byte at a time, which leads to increased latency and low throughput. Thus, there is a need for a novel approach which takes advantage of the increased computing power of newer architectures. This paper presents a method which uses the Cell architecture to run an adapted speculative parallel pattern matching algorithm. Furthermore, we demonstrate that the advantages brought by our of our approach are significant compared to the serial implementation and other parallel ones. We also emphasize the advantages brought by the characteristics of the Cell architecture.
更多
查看译文
关键词
digital signatures,pattern matching,security of data,software architecture,cell architecture,network intrusion detection systems,network traffic,parallel pattern matching algorithm,regular expression matching,signature matching algorithms,using cell processors,cell architecture,dfa matching,intrusion detection,parallel algorithm
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要