The application of protocol analysis technology in Snort system

Huang Zhi-dong · Journal of Zhengzhou University of Light Industry · 2009

A new and effective detection method,namely,protocol analysis techniques was proposed.The process of network packet protocol analysis is a tree root node from the protocol to a path of leaf nodes.Using the protocol rules for attack,just needs checking a specific field,rather than the entire data packet,thus greatly reducing the computational complexity.Compared to the traditional pattern matching techniques,the use of protocol analysis of the pattern-matching model,can reduce the intercomparison number of each packet from hundreds of millions of times to a few hundred times or dozens of times,so that IDS can handle more data packets,which also solves the packet loss problem of the traditional network intrusion detection systems in high-speed network environment.

Read the paper · More papers on PaperTik