Variable-Stride Pattern Matching for Network Intrusion Detection
碩士 === 國立臺灣大學 === 電機工程學研究所 === 100 === Pattern matching is a research topic that focuses on how to efficiently find strings of expected form in some text. In the network, the communication between the computers can be view as sending string to each other, so the knowledge of pattern matching is used...
Main Authors: | , |
---|---|
Other Authors: | |
Format: | Others |
Language: | en_US |
Published: |
2012
|
Online Access: | http://ndltd.ncl.edu.tw/handle/71987158864247894326 |
id |
ndltd-TW-100NTU05442027 |
---|---|
record_format |
oai_dc |
spelling |
ndltd-TW-100NTU054420272015-10-13T21:45:45Z http://ndltd.ncl.edu.tw/handle/71987158864247894326 Variable-Stride Pattern Matching for Network Intrusion Detection 在網路偵測上可變步伐的樣式比對 Kuang-Min Hsu 徐光民 碩士 國立臺灣大學 電機工程學研究所 100 Pattern matching is a research topic that focuses on how to efficiently find strings of expected form in some text. In the network, the communication between the computers can be view as sending string to each other, so the knowledge of pattern matching is used to detect the content of communication in network. The network instruction detection and prevention, one of application used pattern matching in the network, is try to find the malicious data from the incoming data stream which come from outside network. To find malicious data, the rules that present how malicious data look like are converted into automata. The performance of the automata always determines the performance of detecting system. Variable-stride is base on Winnowing algorithm, and this scheme has more memory efficiency than multi-stride method when it has the same throughput improvement. Every transition in the automata applied variable stride may deal with a variable number of symbols, and reduce number of state transition when detecting, so make detecting process faster. However, this scheme is only applied in string matching. Thus this dissertation extends variable-stride to NFA, and keeps its advantage at the same time. Chin-Laung Lei 雷欽隆 2012 學位論文 ; thesis 37 en_US |
collection |
NDLTD |
language |
en_US |
format |
Others
|
sources |
NDLTD |
description |
碩士 === 國立臺灣大學 === 電機工程學研究所 === 100 === Pattern matching is a research topic that focuses on how to efficiently find strings of expected form in some text. In the network, the communication between the computers can be view as sending string to each other, so the knowledge of pattern matching is used to detect the content of communication in network. The network instruction detection and prevention, one of application used pattern matching in the network, is try to find the malicious data from the incoming data stream which come from outside network. To find malicious data, the rules that present how malicious data look like are converted into automata. The performance of the automata always determines the performance of detecting system.
Variable-stride is base on Winnowing algorithm, and this scheme has more memory efficiency than multi-stride method when it has the same throughput improvement. Every transition in the automata applied variable stride may deal with a variable number of symbols, and reduce number of state transition when detecting, so make detecting process faster. However, this scheme is only applied in string matching. Thus this dissertation extends variable-stride to NFA, and keeps its advantage at the same time.
|
author2 |
Chin-Laung Lei |
author_facet |
Chin-Laung Lei Kuang-Min Hsu 徐光民 |
author |
Kuang-Min Hsu 徐光民 |
spellingShingle |
Kuang-Min Hsu 徐光民 Variable-Stride Pattern Matching for Network Intrusion Detection |
author_sort |
Kuang-Min Hsu |
title |
Variable-Stride Pattern Matching for Network Intrusion Detection |
title_short |
Variable-Stride Pattern Matching for Network Intrusion Detection |
title_full |
Variable-Stride Pattern Matching for Network Intrusion Detection |
title_fullStr |
Variable-Stride Pattern Matching for Network Intrusion Detection |
title_full_unstemmed |
Variable-Stride Pattern Matching for Network Intrusion Detection |
title_sort |
variable-stride pattern matching for network intrusion detection |
publishDate |
2012 |
url |
http://ndltd.ncl.edu.tw/handle/71987158864247894326 |
work_keys_str_mv |
AT kuangminhsu variablestridepatternmatchingfornetworkintrusiondetection AT xúguāngmín variablestridepatternmatchingfornetworkintrusiondetection AT kuangminhsu zàiwǎnglùzhēncèshàngkěbiànbùfádeyàngshìbǐduì AT xúguāngmín zàiwǎnglùzhēncèshàngkěbiànbùfádeyàngshìbǐduì |
_version_ |
1718068304161013760 |