Network packet filtering and deep packet inspection hybrid mechanism for IDS early packet matching

Research output: Chapter in Book/Report/Conference proceedingConference contribution

9 Citations (Scopus)

Abstract

Modern network packet processing applications such as Intrusion Detection System (IDS) perform packet filtering and deep packet inspection (DPI), also known as packet content inspection. Fundamentally, for packet filtering, these applications attempt to use the contents of some header fields of the network, transport and application layers of the packets. While for DPI, these applications use attack signature rules to search for predefined patterns in the packet application header fields or payload data. This paper discusses a hybrid mechanism based on the use of splay tree filters and pattern-matching algorithms to enhance IDS packet filtering and DPI performance, respectively. The proposed mechanism uses network traffic statistics to dynamically optimize the order of the splay tree filters, allowing early acceptance and rejection of network packets. In addition, DPI signature rules are reordered according to their matching frequencies, allowing early packets acceptance. We demonstrate the merit of our mechanism through simulations performed on Snort's string set.

Original languageEnglish
Title of host publicationProceedings - IEEE 30th International Conference on Advanced Information Networking and Applications, IEEE AINA 2016
EditorsLeonard Barolli, Tomoya Enokido, Makoto Takizawa, Antonio J. Jara, Yann Bocchi
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages808-815
Number of pages8
ISBN (Electronic)9781509018574
DOIs
Publication statusPublished - May 19 2016
Event30th IEEE International Conference on Advanced Information Networking and Applications, AINA 2016 - Crans-Montana, Switzerland
Duration: Mar 23 2016Mar 25 2016

Publication series

NameProceedings - International Conference on Advanced Information Networking and Applications, AINA
Volume2016-May
ISSN (Print)1550-445X

Other

Other30th IEEE International Conference on Advanced Information Networking and Applications, AINA 2016
Country/TerritorySwitzerland
CityCrans-Montana
Period3/23/163/25/16

Keywords

  • Binary Search on Prefix Length
  • Deep Packet inspection
  • Network intrusion detection
  • Network traffic statistics
  • Packet filtering
  • Pattern matching
  • Splay Tree

ASJC Scopus subject areas

  • General Engineering

Fingerprint

Dive into the research topics of 'Network packet filtering and deep packet inspection hybrid mechanism for IDS early packet matching'. Together they form a unique fingerprint.

Cite this