• 中国计算机学会会刊
  • 中国科技核心期刊
  • 中文核心期刊
论文

WDawgMatch:An Accurate MultiPattern MatchingAlgorithm in Intrusion Detection Systems

Expand
  •  (1.School of Computer Science and Technology,Southeast University,Nanjing 210096;2.Jiangsu Provincial Key Laboratory of Computer Network Technology,Nanjing 210096;3.Key Laboratory of Computer Network and Information Integration,Nanjing 210096,China)

Received date: 2009-05-18

  Revised date: 2009-09-21

  Online published: 2010-07-25

Abstract

The traditional multipattern matching algorithms like AC,BM do not meet the requirements of online outoforder stream reassembly when NIDS detects attack signature matches within packet payloads. As a famous accurate multipattern matching algorithm, DawgMatch is  generally used in NIDS as it can get the digests of the segment being scanned.Unfortunately,though it promotes the space usage by a 2tuple indexing factor with the help of the DAWA automaton, its matching speed still can not catch up with the need of online linear detection.To promote the performance of DawgMathch,we design a new algorithm WDawgMach based on it. WDawgMach makes use of weighted edges to eliminate the back trace problem of DawgMatch to achieve the linear matching speed.The performance analysis and experience shows that,by sacrificing the preprocessing time,WDawgMach improves the worst time complexity of DawgMatch and makes it comparable to algorithm AC.

Cite this article

NING Zhuo,GONG Jian . WDawgMatch:An Accurate MultiPattern MatchingAlgorithm in Intrusion Detection Systems[J]. Computer Engineering & Science, 2010 , 32(8) : 17 -21 . DOI: 10.3969/j.issn.1007130X.2010.

Outlines

/