TY - GEN
T1 - Single character frequency-based exclusive signature matching scheme
AU - Meng, Yuxin
AU - Li, Wenjuan
AU - Kwok, Lam-For
PY - 2012
Y1 - 2012
N2 - Currently, signature-based network intrusion detection systems (NIDSs) have been widely deployed in various organizations such as universities and companies aiming to identify and detect all kinds of network attacks. However, the big suffering problem is that signature matching in these detection systems is too expensive to their performance in which the cost is at least linear to the size of an input string and the CPU occupancy rate can reach more than 80 percent in the worst case. This problem is a key limiting factor to encumber higher performance of a signature-based NIDS under a large-scale network. In this paper, we developed an exclusive signature matching scheme based on single character frequency to improve the efficiency of traditional signature matching. In particular, our scheme calculates the single character frequency from both stored and matched NIDS signatures. In terms of a decision algorithm, our scheme can adaptively choose the most appropriate character for conducting the exclusive signature matching in distinct network contexts. In the experiment, we implemented our scheme in a constructed network environment and the experimental results show that our scheme offers over-all improvements in signature matching. © 2012 Springer-Verlag Berlin Heidelberg.
AB - Currently, signature-based network intrusion detection systems (NIDSs) have been widely deployed in various organizations such as universities and companies aiming to identify and detect all kinds of network attacks. However, the big suffering problem is that signature matching in these detection systems is too expensive to their performance in which the cost is at least linear to the size of an input string and the CPU occupancy rate can reach more than 80 percent in the worst case. This problem is a key limiting factor to encumber higher performance of a signature-based NIDS under a large-scale network. In this paper, we developed an exclusive signature matching scheme based on single character frequency to improve the efficiency of traditional signature matching. In particular, our scheme calculates the single character frequency from both stored and matched NIDS signatures. In terms of a decision algorithm, our scheme can adaptively choose the most appropriate character for conducting the exclusive signature matching in distinct network contexts. In the experiment, we implemented our scheme in a constructed network environment and the experimental results show that our scheme offers over-all improvements in signature matching. © 2012 Springer-Verlag Berlin Heidelberg.
KW - Intelligent system
KW - Intrusion detection
KW - Network security
KW - Signature matching
UR - http://www.scopus.com/inward/record.url?scp=84863192150&partnerID=8YFLogxK
UR - https://www.scopus.com/record/pubmetrics.uri?eid=2-s2.0-84863192150&origin=recordpage
U2 - 10.1007/978-3-642-30454-5_5
DO - 10.1007/978-3-642-30454-5_5
M3 - RGC 32 - Refereed conference paper (with host publication)
SN - 9783642304538
T3 - Studies in Computational Intelligence
SP - 67
EP - 80
BT - Computer and Information Science 2012
PB - Springer
ER -