首页> 外文会议>Information and Communications Security >Space-Economical Reassembly for Intrusion Detection System
【24h】

Space-Economical Reassembly for Intrusion Detection System

机译:入侵检测系统的空间经济重组

获取原文

摘要

The reassembly of IP fragments and TCP streams are very important in Intrusion Detection Systems (IDS). However, existing reassembly algorithms that cache fragments entirely are memory-greedy. It is vulnerable to memory exhaustion denial of service (DOS) attacks. In this paper, we present a space-economical algorithm based on enhanced DAWG (Directed Acyclic Word Graph) automaton, which can detect the occurrences of a set of patterns in an out-of-order data stream. In contrast to existing algorithms, our algorithm scans each fragment by a multi-pattern matching automaton and just caches the returned solid-size index data structures, thus the memory requirement involved in caching fragments is largely reduced. Experiments and analysis show that our new algorithm greatly reduces the memory usage of reassembly in IDS and outperforms existing algorithms.
机译:IP片段和TCP流的重组在入侵检测系统(IDS)中非常重要。但是,现有的完全缓存片段的重组算法是内存贪婪的。它容易受到内存耗尽拒绝服务(DOS)攻击。在本文中,我们提出了一种基于增强型DAWG(定向无环字图)自动机的节省空间的算法,该算法可以检测乱序数据流中一组模式的出现。与现有算法相比,我们的算法通过多模式匹配自动机扫描每个片段,并仅缓存返回的实尺寸索引数据结构,因此大大减少了缓存片段所涉及的内存需求。实验和分析表明,我们的新算法大大降低了IDS中重组的内存使用量,并且优于现有算法。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号