Variable-Stride Pattern Matching for Network Intrusion Detection

碩士 === 國立臺灣大學 === 電機工程學研究所 === 100 === Pattern matching is a research topic that focuses on how to efficiently find strings of expected form in some text. In the network, the communication between the computers can be view as sending string to each other, so the knowledge of pattern matching is used...

Full description

Bibliographic Details
Main Authors: Kuang-Min Hsu, 徐光民
Other Authors: Chin-Laung Lei
Format: Others
Language:en_US
Published: 2012
Online Access:http://ndltd.ncl.edu.tw/handle/71987158864247894326
id ndltd-TW-100NTU05442027
record_format oai_dc
spelling ndltd-TW-100NTU054420272015-10-13T21:45:45Z http://ndltd.ncl.edu.tw/handle/71987158864247894326 Variable-Stride Pattern Matching for Network Intrusion Detection 在網路偵測上可變步伐的樣式比對 Kuang-Min Hsu 徐光民 碩士 國立臺灣大學 電機工程學研究所 100 Pattern matching is a research topic that focuses on how to efficiently find strings of expected form in some text. In the network, the communication between the computers can be view as sending string to each other, so the knowledge of pattern matching is used to detect the content of communication in network. The network instruction detection and prevention, one of application used pattern matching in the network, is try to find the malicious data from the incoming data stream which come from outside network. To find malicious data, the rules that present how malicious data look like are converted into automata. The performance of the automata always determines the performance of detecting system. Variable-stride is base on Winnowing algorithm, and this scheme has more memory efficiency than multi-stride method when it has the same throughput improvement. Every transition in the automata applied variable stride may deal with a variable number of symbols, and reduce number of state transition when detecting, so make detecting process faster. However, this scheme is only applied in string matching. Thus this dissertation extends variable-stride to NFA, and keeps its advantage at the same time. Chin-Laung Lei 雷欽隆 2012 學位論文 ; thesis 37 en_US
collection NDLTD
language en_US
format Others
sources NDLTD
description 碩士 === 國立臺灣大學 === 電機工程學研究所 === 100 === Pattern matching is a research topic that focuses on how to efficiently find strings of expected form in some text. In the network, the communication between the computers can be view as sending string to each other, so the knowledge of pattern matching is used to detect the content of communication in network. The network instruction detection and prevention, one of application used pattern matching in the network, is try to find the malicious data from the incoming data stream which come from outside network. To find malicious data, the rules that present how malicious data look like are converted into automata. The performance of the automata always determines the performance of detecting system. Variable-stride is base on Winnowing algorithm, and this scheme has more memory efficiency than multi-stride method when it has the same throughput improvement. Every transition in the automata applied variable stride may deal with a variable number of symbols, and reduce number of state transition when detecting, so make detecting process faster. However, this scheme is only applied in string matching. Thus this dissertation extends variable-stride to NFA, and keeps its advantage at the same time.
author2 Chin-Laung Lei
author_facet Chin-Laung Lei
Kuang-Min Hsu
徐光民
author Kuang-Min Hsu
徐光民
spellingShingle Kuang-Min Hsu
徐光民
Variable-Stride Pattern Matching for Network Intrusion Detection
author_sort Kuang-Min Hsu
title Variable-Stride Pattern Matching for Network Intrusion Detection
title_short Variable-Stride Pattern Matching for Network Intrusion Detection
title_full Variable-Stride Pattern Matching for Network Intrusion Detection
title_fullStr Variable-Stride Pattern Matching for Network Intrusion Detection
title_full_unstemmed Variable-Stride Pattern Matching for Network Intrusion Detection
title_sort variable-stride pattern matching for network intrusion detection
publishDate 2012
url http://ndltd.ncl.edu.tw/handle/71987158864247894326
work_keys_str_mv AT kuangminhsu variablestridepatternmatchingfornetworkintrusiondetection
AT xúguāngmín variablestridepatternmatchingfornetworkintrusiondetection
AT kuangminhsu zàiwǎnglùzhēncèshàngkěbiànbùfádeyàngshìbǐduì
AT xúguāngmín zàiwǎnglùzhēncèshàngkěbiànbùfádeyàngshìbǐduì
_version_ 1718068304161013760