Title: High-speed string matching for network intrusion detection

Authors: Benfano Soewito, Atul Mahajan, Ning Weng, Haibo Wang

Addresses: Department of Electrical and Computer Engineering, Southern Illinois University, Carbondale, IL 62901, USA. ' Department of Electrical and Computer Engineering, Southern Illinois University, Carbondale, IL 62901, USA. ' Department of Electrical and Computer Engineering, Southern Illinois University, Carbondale, IL 62901, USA. ' Department of Electrical and Computer Engineering, Southern Illinois University, Carbondale, IL 62901, USA

Abstract: Intrusion detection systems are promising techniques to improve internet security. A daunting challenge in the design of internet intrusion detection systems is how to perform high-speed string matching operations. This paper presents a string matching architecture, consisting of software based classifiers and hardware based verifiers. Based on incoming packet contents, the packet classifiers can dramatically reduce the number of strings to be matched and accordingly, feed the packet to a proper verifier to conduct matching. The paper presents the proposed classifier architecture and discusses the trade-offs in the classifier design. In addition, techniques, including multi-threading FSM, high-speed FSM interface circuits and interconnects for high-speed verifier implementation on FPGA platforms are discussed. Experimental results are presented to explore the trade-offs between system performance, strings partition granularity and hardware resource cost.

Keywords: FPGA; string matching; network intrusion detection systems; NIDS; internet security; packet classifiers; classifier design; system performance; string partition granularity; hardware resource cost.

DOI: 10.1504/IJCNDS.2009.027597

International Journal of Communication Networks and Distributed Systems, 2009 Vol.3 No.4, pp.319 - 339

Published online: 03 Aug 2009 *

Full-text access for editors Full-text access for subscribers Purchase this article Comment on this article