TY - GEN
T1 - An evaluation of single character frequency-based exclusive signature matching in distinct IDS environments
AU - Meng, Weizhi
AU - Li, Wenjuan
AU - Kwok, Lam-For
PY - 2014
Y1 - 2014
N2 - The signature-based intrusion detection systems are one of the most commonly used software to protect computer networks by comparing incoming traffic with stored signatures. However, the process of signature matching is a key challenge, in which the workload is generally at least linear to the size of a target string. To solve this problem, exclusive signature matching (ESM) has been proposed based on the observation that most network packets would not match any IDS signatures. But this kind of schemes like the single character frequency-based ESM has not been extensively evaluated. In this paper, our interests are to verify the observation above and evaluate the single character frequency-based ESM in regular networks and hostile environments respectively. In the hostile experiment, we specifically design two malicious situations to test the scheme performance. The experimental results show that the single character frequency-based ESM works fine in a regular network, but its performance would be greatly decreased in a hostile environment. © Springer International Publishing Switzerland 2014
AB - The signature-based intrusion detection systems are one of the most commonly used software to protect computer networks by comparing incoming traffic with stored signatures. However, the process of signature matching is a key challenge, in which the workload is generally at least linear to the size of a target string. To solve this problem, exclusive signature matching (ESM) has been proposed based on the observation that most network packets would not match any IDS signatures. But this kind of schemes like the single character frequency-based ESM has not been extensively evaluated. In this paper, our interests are to verify the observation above and evaluate the single character frequency-based ESM in regular networks and hostile environments respectively. In the hostile experiment, we specifically design two malicious situations to test the scheme performance. The experimental results show that the single character frequency-based ESM works fine in a regular network, but its performance would be greatly decreased in a hostile environment. © Springer International Publishing Switzerland 2014
KW - Exclusive Signature Matching
KW - Intrusion Detection
KW - Network Security
KW - Performance Evaluation
KW - Single Character Frequency
UR - https://www.scopus.com/pages/publications/84921366340
UR - https://www.scopus.com/record/pubmetrics.uri?eid=2-s2.0-84921366340&origin=recordpage
U2 - 10.1007/978-3-319-13257-0_29
DO - 10.1007/978-3-319-13257-0_29
M3 - RGC 32 - Refereed conference paper (with host publication)
SN - 9783319132563
T3 - Lecture Notes in Computer Science
SP - 465
EP - 476
BT - Information Security
A2 - Chow, Sherman S.M.
A2 - Camenisch, Jan
A2 - Hui, Lucas C.K.
A2 - Yiu, Siu Ming
PB - Springer
CY - Cham
T2 - 17th International Conference on Information Security (ISC 2014)
Y2 - 12 October 2014 through 14 October 2014
ER -