Multi-byte Regular Expression Matching with Speculation

被引:0
作者
Luchaup, Daniel [1 ]
Smith, Randy [1 ]
Estan, Cristian [2 ]
Jha, Somesh [1 ]
机构
[1] Univ Wisconsin, Madison, WI 53706 USA
[2] NetLog Microsyst, Santa Clara, CA USA
来源
RECENT ADVANCES IN INTRUSION DETECTION, PROCEEDINGS | 2009年 / 5758卷
关键词
low latency; parallel pattern matching; regular expressions; speculative pattern matching; multi-byte; multi-byte matching; INTRUSION DETECTION;
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Intrusion prevention systems determine whether incoming traffic matches a database of signatures, where each signature in the database represents an attack or a vulnerability. IPSs need to keep up with ever-increasing line speeds, which leads to the use of custom hardware. A major bottleneck that IPSs face is that they scan incoming packets one byte at a time, which limits their throughput and latency. In this paper, we present a method for scanning multiple bytes in parallel using speculation. We break the packet in several chunks, opportunistically scan them in parallel and if the speculation is wrong, correct it later. We present algorithms that apply speculation in single-threaded software running on commodity processors as well as algorithms for parallel hardware. Experimental results show that speculation leads to improvements in latency and throughput in both cases.
引用
收藏
页码:284 / +
页数:3
相关论文
共 30 条
  • [1] ALICHERRY M, 2006, ICNP NOV
  • [2] BECCHI M, 2007, ANCS 2007
  • [3] BECCHI M, 2008, P 2008 ACM IEEE S AR
  • [4] Brodie BC, 2006, CONF PROC INT SYMP C, P191, DOI 10.1145/1150019.1136500
  • [5] BRUMLEY D, 2006, IEEE S SEC PRIV MAY
  • [6] CLARK CR, 2004, IEEE FCCM APR
  • [7] Fast and scalable pattern matching for network intrusion detection systems
    Dharmapurikar, Sarang
    Lockwood, John W.
    [J]. IEEE JOURNAL ON SELECTED AREAS IN COMMUNICATIONS, 2006, 24 (10) : 1781 - 1792
  • [8] An Improved DFA for Fast Regular Expression Matching
    Ficara, Domenico
    Giordano, Stefano
    Procissi, Gregorio
    Vitucci, Fabio
    Antichi, Gianni
    Di Pietro, Andrea
    [J]. ACM SIGCOMM COMPUTER COMMUNICATION REVIEW, 2008, 38 (05) : 31 - 40
  • [9] Handley Mark., 2001, USENIX SECURITY
  • [10] DATA PARALLEL ALGORITHMS
    HILLIS, WD
    STEELE, GL
    [J]. COMMUNICATIONS OF THE ACM, 1986, 29 (12) : 1170 - 1183