A parallel algorithm for protocol reassembling

Xiaoling Zhao, Jizhou Sun, Shishi Liu, Zunce Wei · 2004

In this paper, we devise and implement a parallel protocol reassembling algorithm in application layer for large scale network intruding. Conventional network intrusion detection systems (NIDS) scan the incoming IP packets and judge the attack types by the sensitive information matching. In our algorithm the IP fragments and the TCP stream are reassembled into an entire datagram in the application layer in parallel which is searched for sensitive field. This increases performance even under hostile loads and enables efficient intrusion detection in high speed networks. A high-performance parallel protocol reassembling algorithm is presented and implemented with SMTP protocol.

Read the paper · More papers on PaperTik