首页> 外文会议>International Conference on Communications and Networking in China >A multiple regular expressions matching architecture for network intrusion detection system
【24h】

A multiple regular expressions matching architecture for network intrusion detection system

机译:网络入侵检测系统的多个正则表达式匹配架构

获取原文

摘要

Regular expressions are increasingly used in network security applications. Multiple regular expressions matching is one of the most important performance bottlenecks in those systems. This paper proposes a new hardware-based multiple regular-expressions matching architecture, called MRM, for network intrusion detection system. It shows that traditional algorithm, such as AC, has to face the serious spatial explosion problem when simultaneously detecting a large number of regular expressions because of constrained repetitions. MRM utilizes hardware RAM modules to share matching signals and exploits hardware register counting to implement constrained repetitions. This paper also proposes a software compiler to construct the hardware architecture and generate information in MRM??s RAMs for the given regular expressions. Experiments in actual snort and bro regular expression sets show that MRM can achieve the high throughput of 2.1Gbps and 2.8Gbps on Virtex2 and Virtex4 devices respectively.
机译:正则表达式越来越多地用于网络安全应用程序。多个正则表达式匹配是这些系统中最重要的性能瓶颈之一。本文提出了一种新的基于硬件的多个常规表达式匹配架构,称为MRM,用于网络入侵检测系统。它显示传统算法,例如AC,必须在同时检测由于被限制的重复而检测大量正则表达式时面临严重的空间爆炸问题。 MRM利用硬件RAM模块来共享匹配信号并利用硬件寄存器计数以实现受约束的重复。本文还提出了一种软件编译器来构建硬件架构并在MRM的RAM中为给定的正则表达式生成信息。实际Snort和兄弟正则表达式的实验表明,MRM可以分别在Virtex2和Virtex4设备上实现2.1Gbps和2.8Gbps的高吞吐量。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号