Rule indexing for efficient intrusion detection systems

  • Kang, Boojoong
  • Kim, Hye Seon
  • Yang, Ji Su
  • Im, Eul Gyu
Citations

SCOPUS

3

초록

As the use of the Internet has increased tremendously, the network traffic involved in malicious activities has also grown significantly. To detect and classify such malicious activities, Snort, the open-sourced network intrusion detection system, is widely used. Snort examines incoming packets with all Snort rules to detect potential malicious packets. Because the portion of malicious packets is usually small, it is not efficient to examine incoming packets with all Snort rules. In this paper, we apply two indexing methods to Snort rules, Prefix Indexing and Random Indexing, to reduce the number of rules to be examined. We also present experimental results with the indexing methods.

키워드

indexingintrusion detection systemNetwork securitypattern matchingSnortIncoming packetsIndexing methodsintrusion detection systemIntrusion Detection SystemsMalicious activitiesMalicious packetsNetwork intrusion detection systemsNetwork trafficRandom indexingSnortComputer crimeIntrusion detectionNetwork securityPattern matchingWebsitesIndexing (of information)
제목
Rule indexing for efficient intrusion detection systems
저자
Kang, BoojoongKim, Hye SeonYang, Ji SuIm, Eul Gyu
DOI
10.1007/978-3-642-27890-7_11
발행일
2011-08
유형
Conference Paper
저널명
Lecture Notes in Computer Science
7115 LNCS
페이지
136 ~ 141