Skip to main navigation Skip to search Skip to main content

Piranha: Fast and memory-efficient pattern matching for intrusion detection

  • S. Antonatos
  • , M. Polychronakis
  • , P. Akritidis
  • , K. G. Anagnostakis
  • , E. P. Markatos
  • Foundation for Research and Technology-Hellas
  • University of Pennsylvania

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

17 Scopus citations

Abstract

Network Intrusion Detection Systems (NIDS) provide an important security function to help defend against network attacks. As network speeds and detection workloads increase, it is important for NIDSes to be highly efficient. Most NIDSes need to check for thousands of known attack patterns in every packet, making pattern matching the most expensive part of signature-based NIDSes in terms of processing and memory resources. This paper describes Piranha, a new algorithm for pattern matching tailored specifically for intrusion detection. Piranha is based on the observation that if the rarest substring of a pattern does not appear, then the whole pattern will definitely not match. Our experimental results, based on traces that represent typical NIDS workloads, indicate that Piranha can enhance the performance of a NIDS by 11% to 28% in terms of processing time and by 18% to 73% in terms of memory usage compared to existing NIDS pattern matching algorithms.

Original languageEnglish
Title of host publicationSecurity and Privacy in the Age of Ubiquitous Computing - IFIP TC11 20th International Information Security Conference
EditorsSihan Qing, Eiji Okamoto, Hiroshi Yoshiura, Ryoichi Sasaki
PublisherSpringer New York LLC
Pages393-408
Number of pages16
ISBN (Print)9780387256580
DOIs
StatePublished - 2005
EventIFIP TC11 20th International Information Security Conference, IFIP/SEC2005 - Chiba, Japan
Duration: May 30 2005Jun 1 2005

Publication series

NameIFIP Advances in Information and Communication Technology
Volume181
ISSN (Print)1868-4238

Conference

ConferenceIFIP TC11 20th International Information Security Conference, IFIP/SEC2005
Country/TerritoryJapan
CityChiba
Period05/30/0506/1/05

Keywords

  • intrusion detection
  • network monitoring
  • network performance
  • network security
  • pattern matching

Fingerprint

Dive into the research topics of 'Piranha: Fast and memory-efficient pattern matching for intrusion detection'. Together they form a unique fingerprint.

Cite this