Efficient DFA grouping for traffic identification

Rafael Antonello, Stênio Fernandes, Alysson Santos, Djamel Fawzi Hadj Sadok, Géza Szabó · 2012

Traffic Identification is a key function performed by Internet Service Providers' (ISP) administrators to evaluate and improve network services. However, traffic identification needs to be done in real-time and at wire speed to be useful for network tuning. Deep Packet Inspection (DPI) is widely used for identifying normal applications and attacks in the network by looking for well-known patterns within the packets. Such patterns are mostly expressed by Regular Expressions (RE), which are then evaluated by abstract machines known as Deterministic Finite Automata (DFA). Some previous studies grouped DFAs together to evaluate multiple patterns on a single DFA match's run. Efficient grouping algorithms would combine several DFAs without exceeding the available machine's memory. This work proposes and evaluates a new method to combine several DFAs into a single one. Additionally we compared this algorithm to state-of-the-art approaches using a compressed DFA model. Experimental results show that our algorithm generates less groups and transitions than existent algorithms.

Read the paper · More papers on PaperTik