An Approach for Unifying Rule Based Deep Packet Inspection

被引:0
|
作者
Munoz, A. [1 ]
Sezer, S. [1 ]
Burns, D. [1 ]
Douglas, G. [1 ]
机构
[1] Queens Univ Belfast, CSIT, Belfast, Antrim, North Ireland
关键词
D O I
暂无
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
High performance Internet traffic inspection and layer-7 content analysis have become essential functions of high speed networks. Over the past decade several DPI systems have evolved targeting specific issues related to traffic management, user/application policing, intrusion detection/prevention, URL/malicious/unwanted content filtering. Snort, OpenDPI, Bro, L7-filter, ClamAV are a number of open-source tools based on custom DPI engines and custom rule-sets. The surging demand for higher bandwidth DPI systems capable of supporting larger rule-sets requires the use of hardware acceleration and hardware-based systems. In comparison to software based systems, the design and development of custom purpose hardware for DPI is expensive and enforces the need for a unified DPI system that can be used for a wide range of DPI applications. This paper presents the research in converting known DPI rule-sets into a meta format based on regular expression, that can be executed by a software and hardware-based processing platforms. To demonstrate this work a Snort2Regex translator has been developed to transform Snort rules into regular expressions using not only the content of the Snort rule but every relevant element that belongs to it and could increase the accuracy of the analysis.
引用
收藏
页数:5
相关论文
共 50 条
  • [1] A P4-Based Packet Scheduling Approach for Clustered Deep Packet Inspection Appliances
    Jiang, Ping
    Zhang, Shuo
    Liu, Qingyun
    Zheng, Chao
    [J]. 30TH INTERNATIONAL CONFERENCE ON COMPUTER COMMUNICATIONS AND NETWORKS (ICCCN 2021), 2021,
  • [2] A Novel Approach to Deep Packet Inspection for Intrusion Detection
    Parvat, Thaksen J.
    Chandra, Pravin
    [J]. INTERNATIONAL CONFERENCE ON ADVANCED COMPUTING TECHNOLOGIES AND APPLICATIONS (ICACTA), 2015, 45 : 506 - 513
  • [3] Deep Packet Inspection Research Based On Hardware Acceleration
    Guo Lei
    Wang Yadi
    Zhu Ke
    [J]. 2012 INTERNATIONAL CONFERENCE ON INDUSTRIAL CONTROL AND ELECTRONICS ENGINEERING (ICICEE), 2012, : 1984 - 1986
  • [4] Deep Packet Inspection as a Service
    Bremler-Barr, Anat
    Harchol, Yotam
    Hay, David
    Koral, Yaron
    [J]. PROCEEDINGS OF THE 2014 CONFERENCE ON EMERGING NETWORKING EXPERIMENTS AND TECHNOLOGIES (CONEXT'14), 2014, : 271 - 282
  • [5] Elastic Deep Packet Inspection
    Watson, Bruce W.
    [J]. 2014 6TH INTERNATIONAL CONFERENCE ON CYBER CONFLICT (CYCON 2014), 2014, : 241 - 253
  • [6] A Survey on Deep Packet Inspection
    El-Maghraby, Reham Taher
    Abd Elazim, Nada Mostafa
    Bahaa-Eldin, Ayaman M.
    [J]. 2017 12TH INTERNATIONAL CONFERENCE ON COMPUTER ENGINEERING AND SYSTEMS (ICCES), 2017, : 188 - 197
  • [7] QCF for deep packet inspection
    Al-hisnawi, Mohammad
    Ahmadi, Mahmood
    [J]. IET NETWORKS, 2018, 7 (05) : 346 - 352
  • [8] An improved method in deep packet inspection based on regular expression
    Ruxia Sun
    Lingfeng Shi
    Chunyong Yin
    Jin Wang
    [J]. The Journal of Supercomputing, 2019, 75 : 3317 - 3333
  • [9] NFA-based Pattern Matching for Deep Packet Inspection
    Sun, Yan
    Valgenti, Victor C.
    Kim, Min Sik
    [J]. 2011 20TH INTERNATIONAL CONFERENCE ON COMPUTER COMMUNICATIONS AND NETWORKS (ICCCN), 2011,
  • [10] An improved method in deep packet inspection based on regular expression
    Sun, Ruxia
    Shi, Lingfeng
    Yin, Chunyong
    Wang, Jin
    [J]. JOURNAL OF SUPERCOMPUTING, 2019, 75 (06): : 3317 - 3333