An Efficient String Matching Algorithm Using Bidirectional and Parallel Processing Structure for Intrusion Detection System

Gwo-Ching Chang · KSII Transactions on Internet and Information Systems · 2010

Rapid growth of internet applications has increased the importance of intrusion detection system (IDS) performance. String matching is the most computation-consuming task in IDS.In this paper, a new algorithm for multiple string matching is proposed.This proposed algorithm is based on the canonical Aho-Corasick algorithm and it utilizes a bidirectional and parallel processing structure to accelerate the matching speed.The proposed string matching algorithm was implemented and patched into Snort for experimental evaluation.Comparing with the canonical Aho-Corasick algorithm, the proposed algorithm has gained much improvement on the matching speed, especially in detecting multiple keywords within a long input text string.

Read the paper · More papers on PaperTik