Network packet filtering and deep packet inspection hybrid mechanism for IDS early packet matching

    Research output: Chapter in Book/Report/Conference proceedingConference contribution

    8 Citations (Scopus)

    Abstract

    Modern network packet processing applications such as Intrusion Detection System (IDS) perform packet filtering and deep packet inspection (DPI), also known as packet content inspection. Fundamentally, for packet filtering, these applications attempt to use the contents of some header fields of the network, transport and application layers of the packets. While for DPI, these applications use attack signature rules to search for predefined patterns in the packet application header fields or payload data. This paper discusses a hybrid mechanism based on the use of splay tree filters and pattern-matching algorithms to enhance IDS packet filtering and DPI performance, respectively. The proposed mechanism uses network traffic statistics to dynamically optimize the order of the splay tree filters, allowing early acceptance and rejection of network packets. In addition, DPI signature rules are reordered according to their matching frequencies, allowing early packets acceptance. We demonstrate the merit of our mechanism through simulations performed on Snort's string set.

    Original languageEnglish
    Title of host publicationProceedings - IEEE 30th International Conference on Advanced Information Networking and Applications, IEEE AINA 2016
    PublisherInstitute of Electrical and Electronics Engineers Inc.
    Pages808-815
    Number of pages8
    Volume2016-May
    ISBN (Electronic)9781509018574
    DOIs
    Publication statusPublished - May 19 2016
    Event30th IEEE International Conference on Advanced Information Networking and Applications, AINA 2016 - Crans-Montana, Switzerland
    Duration: Mar 23 2016Mar 25 2016

    Other

    Other30th IEEE International Conference on Advanced Information Networking and Applications, AINA 2016
    Country/TerritorySwitzerland
    CityCrans-Montana
    Period3/23/163/25/16

    Keywords

    • Binary Search on Prefix Length
    • Deep Packet inspection
    • Network intrusion detection
    • Network traffic statistics
    • Packet filtering
    • Pattern matching
    • Splay Tree

    ASJC Scopus subject areas

    • Engineering(all)

    Fingerprint

    Dive into the research topics of 'Network packet filtering and deep packet inspection hybrid mechanism for IDS early packet matching'. Together they form a unique fingerprint.

    Cite this