Fast Multipattern Matching for Intrusion Detection - INRIA - Institut National de Recherche en Informatique et en Automatique Accéder directement au contenu
Communication Dans Un Congrès Année : 2004

Fast Multipattern Matching for Intrusion Detection

Résumé

Misuse intrusion detection (IDS) detects signatures of attack scenarios. Hackers try to avoid detection by permuting actions, and inserting, hiding or overlapping packets. Stateful detection becomes thus essential to suitably supervise network traffic. We propose in this paper a new approach for analysing the network traffic. The inspection, while being stateful, processes each packet as soon as it is received. We have used this strategy with appropriate multi-search methods and adequate datastructures for signatures.

Domaines

Autre [cs.OH]
Fichier non déposé

Dates et versions

inria-00100007 , version 1 (26-09-2006)

Identifiants

  • HAL Id : inria-00100007 , version 1

Citer

Tarek Abbes, Michaël Rusinowitch. Fast Multipattern Matching for Intrusion Detection. 13th Annual Conference on European Institute for Computer Anti-virus Research - EICAR'2004, May 2004, Luxemburg, Luxembourg, 22 p. ⟨inria-00100007⟩
73 Consultations
0 Téléchargements

Partager

Gmail Facebook X LinkedIn More