Approximate reduction of finite automata for high-speed network intrusion detection

被引:4
|
作者
Ceska, Milan [1 ]
Havlena, Vojtech [1 ]
Holik, Lukas [1 ]
Lengal, Ondrej [1 ]
Vojnar, Tomas [1 ]
机构
[1] Brno Univ Technol, FIT, Ctr Excellence IT4Innovat, Brno, Czech Republic
关键词
Reduction; Nondeterministic finite automata; Deep packet inspection; High-speed network monitoring; ARCHITECTURE;
D O I
10.1007/s10009-019-00520-8
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
We consider the problem ofapproximate reduction of non-deterministic automatathat appear in hardware-accelerated network intrusion detection systems (NIDSes). We define an errordistanceof a reduced automaton from the original one as the probability of packets being incorrectly classified by the reduced automaton (wrt the probabilistic distribution of packets in the network traffic). We use this notion to design anapproximate reduction procedurethat achieves a great size reduction (much beyond the state-of-the-art language-preserving techniques) with a controlled and small error. We have implemented our approach and evaluated it on use cases fromSnort, a popular NIDS. Our results provide experimental evidence that the method can be highly efficient in practice, allowing NIDSes to follow the rapid growth in the speed of networks.
引用
下载
收藏
页码:523 / 539
页数:17
相关论文
共 50 条
  • [31] Real-time intrusion detection for high-speed networks
    Jiang, WB
    Song, H
    Dai, YQ
    COMPUTERS & SECURITY, 2005, 24 (04) : 287 - 294
  • [32] Smart architecture for high-speed intrusion detection and prevention systems
    Wu, Chih-Chiang
    Wen, Sung-Hua
    Huang, Nen-Fu
    CRYPTOLOGY AND NETWORK SECURITY, PROCEEDINGS, 2006, 4301 : 318 - 328
  • [33] Hardware Acceleration of Intrusion Detection Systems for High-Speed Networks
    Kucera, Jan
    Kekely, Lukas
    Pus, Viktor
    Piecek, Adam
    Korenek, Jan
    PROCEEDINGS OF THE 2018 SYMPOSIUM ON ARCHITECTURES FOR NETWORKING AND COMMUNICATIONS SYSTEMS (ANCS '18), 2018, : 177 - 178
  • [34] Intrusion detection for high-speed railways based on unsupervised anomaly detection models
    Yao Wang
    Zujun Yu
    Liqiang Zhu
    Applied Intelligence, 2023, 53 : 8453 - 8466
  • [35] Intrusion detection for high-speed railways based on unsupervised anomaly detection models
    Wang, Yao
    Yu, Zujun
    Zhu, Liqiang
    APPLIED INTELLIGENCE, 2023, 53 (07) : 8453 - 8466
  • [36] Research on High-speed Network-based Intrusion Prevention System
    Gu, Chunying
    Gu, Dawei
    2010 6TH INTERNATIONAL CONFERENCE ON WIRELESS COMMUNICATIONS NETWORKING AND MOBILE COMPUTING (WICOM), 2010,
  • [37] Capacity verification for high speed network intrusion detection systems
    Hall, M
    Wiley, K
    RECENT ADVANCES IN INTRUSION DETECTION, PROCEEDINGS, 2002, 2516 : 239 - 251
  • [38] A 10-Gbps high-speed single-chip Network Intrusion Detection and Prevention System
    Artan, N. Sertac
    Ghosh, Rajdip
    Guo, Yanchuan
    Chao, H. Jonathan
    GLOBECOM 2007: 2007 IEEE GLOBAL TELECOMMUNICATIONS CONFERENCE, VOLS 1-11, 2007, : 343 - 348
  • [39] High Speed Network Intrusion Detection System Using FPGA
    Anuraj, S.
    Premalatha, P.
    Gireeshkumar, T.
    PROCEEDINGS OF THE SECOND INTERNATIONAL CONFERENCE ON COMPUTER AND COMMUNICATION TECHNOLOGIES, IC3T 2015, VOL 1, 2016, 379 : 187 - 194
  • [40] Towards Multi-layered Intrusion Detection in High-Speed Networks
    Golling, Mario
    Hofstede, Rick
    Koch, Robert
    2014 6TH INTERNATIONAL CONFERENCE ON CYBER CONFLICT (CYCON 2014), 2014, : 191 - +