Analysis of pattern matching algorithms in network intrusion detection systems
Vishwajeet Dagar, Vatsal Prakash, Tarunpreet Bhatia · 2016
Pattern-Matching algorithms are vastly being implemented in the NIDS (Network Intrusion Detection Systems) nowadays in order to keep a check on any malicious activities of any trespasser. With an increase in Network traffic with time, the pattern-matching algorithms should be quick so as to keep a check and keep up with the network speed. Hence, it is very important to choose the right algorithm for our purpose in order to get the work done with ease and in a quick manner. Although there are many pattern-matching algorithms that exist but we decided to take into consideration some majorly popular ones which include: Naive approach, Knuth-MorrisPratt algorithm, RabinKarp Algorithm and also the trie data structure which is still not that popular in this field but we believe can be helpful in the future. The above mentioned algorithms are compared in order to check which of them is most efficient in pattern/Intrusion detection. Pcap files have been used as datasets in order to determine the efficiency of the algorithm by taking into consideration their running times respectively.