Adaptive Pattern Matching Grammar Generation for use in Deep Packet Inspection

被引:0
作者
Menon, Govind [1 ]
Katdare, Sanchit [1 ]
Phatak, Sagar [1 ]
Khengare, Rahul [1 ]
机构
[1] Univ Pune, Pune, Maharashtra, India
来源
UKSIM FIFTH EUROPEAN MODELLING SYMPOSIUM ON COMPUTER MODELLING AND SIMULATION (EMS 2011) | 2011年
关键词
Deep Packet Inspection; Pattern Matching; Grammar; Regular Expressions;
D O I
10.1109/EMS.2011.74
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
Deep Packet Inspection (DPI) is becoming more widely used in virtually all applications or services like Denial of Service (DoS), Intrusion Detection System (IDS) etc. that operate with or within a network. However for a developer or team working on any network project who need to perform DPI, there is always the issue of using a third party source which may involve added cost or implementing it themselves which requires time and study of protocols, signatures and the nuances of pattern matching. The paper proposes a solution to the above problem using an adaptive grammar generation algorithm. This method reduces the entropy among similar results given by different patterns. Immense customizability is the foremost advantage of this method. Existing grammars for new signatures can be combined into a single grammar easily rather than new grammars be generated from raw target strings. The paper, thus, looks to limit the detailed knowledge requirement for the design of signature detection procedures and in doing so re-use existing procedures which have been thoroughly debugged and tested.
引用
收藏
页码:119 / 122
页数:4
相关论文
共 5 条
[1]  
AHO AV, 1975, COMMUNICATIONS ACM
[2]   SPACE-ECONOMICAL SUFFIX TREE CONSTRUCTION ALGORITHM [J].
MCCREIGHT, EM .
JOURNAL OF THE ACM, 1976, 23 (02) :262-272
[3]  
ROESCH M, 1999, P 13 USENIX C SYST A
[4]  
Smith Randy, 2008, P ACM SIGCOMM 2008 C, DOI [10.1145/1402958.1402983, DOI 10.1145/1402958.1402983]]
[5]  
Weiner P., 1973, 14th Annual Symposium on Switching Automata Theory, P1