Fast rule matching in network security systems
Jiwu Jing · 2007
With network attacks increasing,security systems are widely applied,and rule matching is a key factor.Accelerating matching speed improve efficiency,and make security systems suit for higher-speed networks and much stricter environments.Two kind of common matching algorithms are introduced and analysed at first: Boolean expression tree and directed acyclic control flow graph(CFG),and then a better one is put forward.This algorithm does equivalent transformation over CFG at first,does some optimization and improvement with probability,and then adjusts rule's internal logical expression structure.So it gets faster to transform structure and compute.Through testing,this algorithm is shown to take less time and improve performance greatly.