首页> 外文会议>2011 IEEE International Conference on Communications >An Approach for Unifying Rule Based Deep Packet Inspection
【24h】

An Approach for Unifying Rule Based Deep Packet Inspection

机译:一种基于规则的深度包检测统一方法

获取原文

摘要

High performance Internet traffic inspection and layer-7 content analysis have become essential functions of high speed networks. Over the past decade several DPI systems have evolved targeting specific issues related to traffic management, user/application policing, intrusion detection/prevention, URL/malicious/unwanted content filtering. Snort, OpenDPI, Bro, L7-filter, ClamAV are a number of open-source tools based on custom DPI engines and custom rule-sets. The surging demand for higher bandwidth DPI systems capable of supporting larger rule-sets requires the use of hardware acceleration and hardware-based systems. In comparison to software based systems, the design and development of custom purpose hardware for DPI is expensive. The need for DPI solutions for a range of applications at high speed requires a unified processing platform. This paper presents the research in converting known DPI rule-sets into a meta format based on regular expressions, that can be executed by software and hardware-based processing platforms. To demonstrate this work a Snort2Regex translator has been developed to transform Snort rules into regular expressions using not only the content of the Snort rule but every relevant element that belongs to it and could increase the accuracy of the analysis.
机译:高性能Internet流量检查和第7层内容分析已成为高速网络的基本功能。在过去的十年中,一些DPI系统针对与流量管理,用户/应用程序管制,入侵检测/预防,URL /恶意/有害内容过滤有关的特定问题进行了开发。 Snort,OpenDPI,Bro,L7过滤器,ClamAV是许多基于自定义DPI引擎和自定义规则集的开源工具。对于能够支持更大规则集的更高带宽DPI系统的不断增长的需求,要求使用硬件加速和基于硬件的系统。与基于软件的系统相比,用于DPI的定制硬件的设计和开发非常昂贵。对于高速,多种应用的DPI解决方案的需求,需要一个统一的处理平台。本文介绍了将已知DPI规则集转换为基于正则表达式的元格式的研究,该表达式可以由基于软件和硬件的处理平台执行。为了演示这项工作,开发了一个Snort2Regex转换器,不仅使用Snort规则的内容,而且还使用属于Snort2Regex的每个相关元素,将Snort规则转换为正则表达式,并可以提高分析的准确性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号