Towards faster string matching for intrusion detection or exceeding the speed of Snort
C.J. Coit, Stuart Staniford, Joey McAlerney · 2002
Network intrusion detection systems (NIDS) often rely on exact string matching techniques. Depending on the choice of algorithm, implementation and the frequency with which it is applied, this pattern matching may become a performance bottleneck. To keep up with increasing network speeds and traffic, NIDS can take advantage of advanced string matching algorithms. We describe the effectiveness of a significantly faster approach to pattern matching in the open source NIDS Snort.