Integrating Aho-Corasick based algorithm for Compressed Trac (ACCH) Inside Snort

Adir Gabai, Anat Bremler-Bar, Yaron Koral · 2015

Snort is a very popular network intrusion detection system (NIDS). One of its main methods of inspection is to scan the traffic payload for malicious content. Unfortunately, Snort deals with compressed http traffic in a naive way. It first decompresses the traffic, and then performs a multi-pattern matching scan. Thus, Snort suffers from a performance penalty in pattern matching on compressed http data. Recently, an algorithm that tackles the above problem, called ACCH, was proposed. The algorithm presented impressive performance results on simulation environment but not on a real Snort setup. In this work we present the integration of ACCH algorithm inside Snort in order to improve the performance over compressed http traffic. However, the improvement was not significant as expected. We show an analysis of ACCH algorithm and a comparison between our implementation and the original implementation of ACCH. Our analysis reveals a new set of properties, which are relevant when trying to incorporate an algorithm with Snort. The original ACCH paper assumed a simplified model which should be extended to include the properties we found. We modify the original algorithm to support these properties and suggest future directions to improve furthermore the performance of the compressed traffic scanning algorithm.

Read the paper · More papers on PaperTik