Two-Way AC Algorithm and its Application to Intrusion Detection System
CSTR:
Author:
  • Article
  • | |
  • Metrics
  • |
  • Reference [7]
  • |
  • Related [20]
  • |
  • Cited by [0]
  • | |
  • Comments
    Abstract:

    Based on AC algorithm for performing multiple string matching algorithms, two-way AC algorithm was proposed. The algorithm constructs a forward finite automaton and a reversed finite automaton in the preprocessing stage. In the Matching stage it scans the text string from middle to right with a forward finite automaton and concurrently from middle to left with a reversed finite automaton. The algorithm has been implemented by modifying the source code of Snort. The experimental result shows that the time performance of two-way AC algorithm is superior to BM algorithm, WM algorithm and AC algorithm. Efficiency of the algorithm is about 1.5 times AC algorithm if the mode of detection is to discover and stop.

    Reference
    1 Boyer RS, Moore JS. A fast string searching algorithm. Communications of the ACM, 1997,20(10):762-772.
    2 Wu S, Manber U. Fast algorithm for multi-pattern searching. Tucson: Department of computer science university of arizona, 1994.
    3 Aho A, Corasick M. Efficient string matching: An aid to bibliographic search. Communications of the ACM, 1975,18(6): 333-343.
    4 张庆平. 一种基于Snort 的入侵检测系统的实现和应用[硕士学位论文].长春:吉林大学,2008.
    5 高平利,任金昌.基于Snort 入侵检测系统的分析与实现.计算机应用与软件,2006,23(8):134-138.
    6 Roesch M, Green C. Snort users manual. [2009-9-5].https://www.Snort.org/assets/125/Snort_manual-2_8_5_1.pdf
    7 The Shmoo Group. Capture the capture the flag data use statement.[2007-6-15].http://cctf.shmoo.com/data/cctf-defcon10/
    Comments
    Comments
    分享到微博
    Submit
Get Citation

杨超.双向AC 算法及其在入侵检测系统中应用.计算机系统应用,2011,20(3):222-225

Copy
Share
Article Metrics
  • Abstract:2117
  • PDF: 4288
  • HTML: 0
  • Cited by: 0
History
  • Received:July 12,2010
  • Revised:September 16,2010
Article QR Code
You are the first990460Visitors
Copyright: Institute of Software, Chinese Academy of Sciences Beijing ICP No. 05046678-3
Address:4# South Fourth Street, Zhongguancun,Haidian, Beijing,Postal Code:100190
Phone:010-62661041 Fax: Email:csa (a) iscas.ac.cn
Technical Support:Beijing Qinyun Technology Development Co., Ltd.

Beijing Public Network Security No. 11040202500063