CHEN Shu-hui, SUN Zhi-gang, SU Jin-shu. Research on range matching for wire-speed hardware NIDS[J]. 2006, (10): 7-12.DOI:
线速硬件网络入侵检测系统的范围匹配研究
摘要
为解决硬件入侵检测系统的规则匹配问题
提出了一种降低存储资源的范围匹配算法LRC-RM
将规则中的端口范围映射成压缩位向量
并将位向量组织成扩展平衡二叉树
然后对实现的系统进行了评估。采用该技术的网络入侵检测系统
使用的存储空间只有已有算法的1%
有利于硬件在片内完成查找过程
可实现端口范围在OC192链路的线速匹配。
Abstract
To solve the rule matching problem of hardware NIDS
a range matching algorithm LRC-RM was proposed
with more efficient memory utilization.The approach mapped the port range into a compressed bit vector and organized the bit vectors as an extended balanced binary tree.Experiments were employed to show that NIDS using this approach can perform wire-speed range matching for OC-192 links
while saving 99% memory resource comparing to the existing methods.The algorithm is easy to be implemented within a chip without additional RAM.