首页> 外文会议>International Conference on Information and Communications Security >Deep Packet Inspection with Delayed Signature Matching in Network Auditing
【24h】

Deep Packet Inspection with Delayed Signature Matching in Network Auditing

机译:网络审计中延迟签名匹配的深度数据包检查

获取原文
获取外文期刊封面目录资料

摘要

Deep Packet Inspection (DPI) is widely used in network systems and the processing speed of DPI is very critical. The core part of existing DPI is signature matching, and many researchers focus on improving the signature matching algorithms. In this paper, we work from a different angle: the scheduling of signature matching. We propose a method called Delayed Signature Matching (DSM), which could greatly reduce the number of matching attempts. In the method we do not always immediately match received packets to the signatures, but instead we predefine some protocol specific rules, and evaluate the packets against these rules first to decide when to start signature matching and which signatures to match, thus eliminate lots of useless matching attempts. The proposed DSM method is very suitable for the network auditing scenario since recognizing a flow at the earliest possible time is not required, and the potential seconds of delay brought in by DSM is acceptable. We also find that in the DSM method the number of matching attempts for a flow is unrelated to the number of supported protocols, which is a good property since the number of supported protocols keeps growing. Finally, we implement a prototype of the DSM method in the open source DPI library nDPI, and find that it can reduce the signature matching time 27%-40%.
机译:深度数据包检测(DPI)广泛用于网络系统,DPI的处理速度非常关键。现有DPI的核心部分是签名匹配,许多研究人员专注于改善签名匹配算法。在本文中,我们从不同的角度工作:签名匹配的调度。我们提出了一种称为延迟签名匹配(DSM)的方法,可以大大减少匹配尝试的数量。在该方法中,我们并不总是立即将收到的数据包匹配到签名,而是我们预先确定某些协议特定规则,并首先评估对这些规则的数据包来决定何时开始签名匹配,从而消除匹配的签名,从而消除了许多匹配的何种签名,从而消除了许多匹配的签名,从而消除了许多匹配的签名,从而消除了许多匹配的何种签名,从而消除了许多匹配的签名,从而消除了许多匹配的签名,从而消除了许多匹配的签名,从而消除了许多匹配的签名,从而消除了许多匹配的签名,从而消除了许多匹配的签名,从而消除了许多匹配的签名何时毫无用处匹配尝试。所提出的DSM方法非常适合于网络审计场景,因为不需要尽可能少的时间识别流量,并且DSM引入的延迟延迟是可接受的。我们还发现,在DSM方法中,流量的匹配尝试数与支持的协议的数量不相关,这是一个很好的属性,因为支持的协议的数量不断增长。最后,我们在开源DPI库NDPI中实现了DSM方法的原型,并发现它可以减少签名匹配时间27%-40%。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号