Computer Engineering & Science >
WDawgMatch:An Accurate MultiPattern MatchingAlgorithm in Intrusion Detection Systems
Received date: 2009-05-18
Revised date: 2009-09-21
Online published: 2010-07-25
The traditional multipattern matching algorithms like AC,BM do not meet the requirements of online outoforder stream reassembly when NIDS detects attack signature matches within packet payloads. As a famous accurate multipattern matching algorithm, DawgMatch is generally used in NIDS as it can get the digests of the segment being scanned.Unfortunately,though it promotes the space usage by a 2tuple indexing factor with the help of the DAWA automaton, its matching speed still can not catch up with the need of online linear detection.To promote the performance of DawgMathch,we design a new algorithm WDawgMach based on it. WDawgMach makes use of weighted edges to eliminate the back trace problem of DawgMatch to achieve the linear matching speed.The performance analysis and experience shows that,by sacrificing the preprocessing time,WDawgMach improves the worst time complexity of DawgMatch and makes it comparable to algorithm AC.
NING Zhuo,GONG Jian . WDawgMatch:An Accurate MultiPattern MatchingAlgorithm in Intrusion Detection Systems[J]. Computer Engineering & Science, 2010 , 32(8) : 17 -21 . DOI: 10.3969/j.issn.1007130X.2010.
/
| 〈 |
|
〉 |