2010 China-Ireland International Conferenceon Information and CommunicationsTechnologies (CIICT2010 E-BOOK)

Wuhan,China,10.10-10.11,2010

ISBN: 978-1-935068-30-3 Scientific Research Publishing, USA

E-Book 200pp Pub. Date: October 2010

Category: Engineering

Price: $40

Title: Algorithmic Multi-match Packet Classification in Network Intrusion Detection Systems
Source: 2010 China-Ireland International Conferenceon Information and CommunicationsTechnologies (CIICT2010 E-BOOK) (pp 150-156)
Author(s): Brendan Cronin, Network Processing Group, RINCE, School of Electronic Engineering, Dublin City University, Ireland
Xiaojun Wang, Network Processing Group, RINCE, School of Electronic Engineering, Dublin City University, Ireland
Abstract: Multi-match packet classification is the first stage in Network Intrusion Detection Systems where it is followed by Deep Packet Inspection performed on the matching rules. The most commonly proposed solutions to multi-match classification are TCAM based and, as a result, suffer from several disadvantages such as higher cost, energy consumption, and circuit board area. This paper investigates alternative algorithmic solutions that can use SRAM in place of TCAM. We adapt a number of well known single-match packet classification algorithms and compare their multi-match classification performance in terms of memory requirements, energy consumption and packet processing speed. Finally we compare these with two existing multi-match solutions. We conclude that bit vector based architectures perform well thanks to the extensive overlap between the header sections of typical NIDS rule sets which allows significant compression of the number of rule headers.
Free SCIRP Newsletters
Copyright © 2006-2024 Scientific Research Publishing Inc. All Rights Reserved.
Top