基于哈希的短字符串预过滤器提高入侵检测系统的吞吐量

Tomás Fukac, V. Kosar, J. Korenek, J. Matoušek
{"title":"基于哈希的短字符串预过滤器提高入侵检测系统的吞吐量","authors":"Tomás Fukac, V. Kosar, J. Korenek, J. Matoušek","doi":"10.1109/LCN48667.2020.9314812","DOIUrl":null,"url":null,"abstract":"With an increasing speed of network links, it is also necessary to increase the throughput of network security systems. An intrusion detection system (IDS) is one of the key components in the protection of network infrastructure. Unfortunately, the IDS has to match a large set of regular expressions (REs) in network streams, which has a negative impact on its throughput. A fast pre-filtration of network traffic can allow to achieve a higher overall throughput. Therefore, we have designed a new algorithm, which is able to select short strings that represent an RE set utilized in the IDS. Compared to previous methods, strings are selected in less than a second for an RE and can reduce network traffic up to 3.3 times better. As all selected strings have the same length, they can be used in a hash-based pre-filter, which is able to process more 100 Gbps of network traffic.","PeriodicalId":245782,"journal":{"name":"2020 IEEE 45th Conference on Local Computer Networks (LCN)","volume":"1 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2020-11-16","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"1","resultStr":"{\"title\":\"Increasing Throughput of Intrusion Detection Systems by Hash-Based Short String Pre-filter\",\"authors\":\"Tomás Fukac, V. Kosar, J. Korenek, J. Matoušek\",\"doi\":\"10.1109/LCN48667.2020.9314812\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"With an increasing speed of network links, it is also necessary to increase the throughput of network security systems. An intrusion detection system (IDS) is one of the key components in the protection of network infrastructure. Unfortunately, the IDS has to match a large set of regular expressions (REs) in network streams, which has a negative impact on its throughput. A fast pre-filtration of network traffic can allow to achieve a higher overall throughput. Therefore, we have designed a new algorithm, which is able to select short strings that represent an RE set utilized in the IDS. Compared to previous methods, strings are selected in less than a second for an RE and can reduce network traffic up to 3.3 times better. As all selected strings have the same length, they can be used in a hash-based pre-filter, which is able to process more 100 Gbps of network traffic.\",\"PeriodicalId\":245782,\"journal\":{\"name\":\"2020 IEEE 45th Conference on Local Computer Networks (LCN)\",\"volume\":\"1 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2020-11-16\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"1\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2020 IEEE 45th Conference on Local Computer Networks (LCN)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/LCN48667.2020.9314812\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2020 IEEE 45th Conference on Local Computer Networks (LCN)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/LCN48667.2020.9314812","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 1

摘要

随着网络链路速度的不断提高,也需要提高网络安全系统的吞吐量。入侵检测系统(IDS)是保护网络基础设施的关键组成部分之一。不幸的是,IDS必须匹配网络流中的大量正则表达式(REs),这对其吞吐量有负面影响。网络流量的快速预过滤可以实现更高的总体吞吐量。因此,我们设计了一种新的算法,该算法能够选择代表IDS中使用的RE集的短字符串。与以前的方法相比,正则在不到1秒的时间内选择字符串,并且可以将网络流量减少3.3倍。由于所有选择的字符串都具有相同的长度,因此它们可以用于基于哈希的预过滤器,该过滤器能够处理100 Gbps以上的网络流量。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
Increasing Throughput of Intrusion Detection Systems by Hash-Based Short String Pre-filter
With an increasing speed of network links, it is also necessary to increase the throughput of network security systems. An intrusion detection system (IDS) is one of the key components in the protection of network infrastructure. Unfortunately, the IDS has to match a large set of regular expressions (REs) in network streams, which has a negative impact on its throughput. A fast pre-filtration of network traffic can allow to achieve a higher overall throughput. Therefore, we have designed a new algorithm, which is able to select short strings that represent an RE set utilized in the IDS. Compared to previous methods, strings are selected in less than a second for an RE and can reduce network traffic up to 3.3 times better. As all selected strings have the same length, they can be used in a hash-based pre-filter, which is able to process more 100 Gbps of network traffic.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Leveraging MEC in a 5G System for Enhanced Back Situation Awareness L3SFA: Load Shifting Strategy for Spreading Factor Allocation in LoRaWAN Systems PLEDGE: An IoT-oriented Proof-of-Honesty based Blockchain Consensus Protocol Don’t Stop at the Top: Using Certificate Transparency Logs to Extend Domain Lists for Web Security Studies SETA: Scalable Encrypted Traffic Analytics in Multi-Gbps Networks
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1