Skip to main navigation Skip to search Skip to main content

E2XB: A domain-specific string matching algorithm for intrusion detection

  • Foundation for Research and Technology-Hellas
  • University of Pennsylvania

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

52 Scopus citations

Abstract

We consider the problem of string matching in Network Intrusion Detection Systems (NIDSes). String matching computations dominate in the overall cost of running a NIDS, despite the use of efficient general-purpose string matching algorithms. Aiming at increasing the efficiency and capacity of NIDSes, we have designed E2xB, a string matching algorithm that is tailored to the specific characteristics of NIDS string matching. We have implemented E2xB in snort, a popular open-source NIDS, and present experiments comparing E2xB with the current best alternative solution. Our results suggest that for typical traffic patterns E2xB improves NIDS performance by 10%-36%, while for certain rule set and traffic patterns string matching performance can be improved by as much as a factor of three.

Original languageEnglish
Title of host publicationSecurity and Privacy in the age of Uncertainty - IFIP TC11 18th International Conference on Information Security, SEC 2003
PublisherSpringer New York LLC
Pages217-229
Number of pages13
ISBN (Print)9781475764895
DOIs
StatePublished - 2003
EventIFIP TC11 18th International Conference on Information Security, SEC 2003 - Athens, Greece
Duration: May 26 2003May 28 2003

Publication series

NameIFIP Advances in Information and Communication Technology
Volume122
ISSN (Print)1868-4238

Conference

ConferenceIFIP TC11 18th International Conference on Information Security, SEC 2003
Country/TerritoryGreece
CityAthens
Period05/26/0305/28/03

Keywords

  • Intrusion detection
  • Network monitoring
  • Network performance
  • Network security
  • String matching

Fingerprint

Dive into the research topics of 'E2XB: A domain-specific string matching algorithm for intrusion detection'. Together they form a unique fingerprint.

Cite this