首页> 外文会议>Recent advances in intrusion detection >High-Speed Matching of Vulnerability Signatures
【24h】

High-Speed Matching of Vulnerability Signatures

机译:高速匹配漏洞签名

获取原文
获取原文并翻译 | 示例

摘要

Vulnerability signatures offer better precision and flexibility than exploit signatures when detecting network attacks. We show that it is possible to detect vulnerability signatures in high-performance network intrusion detection systems, by developing a matching architecture that is specialized to the task of vulnerability signatures. Our architecture is based upon: ⅰ) the use of high-speed pattern matchers, together with control logic, instead of recursive parsing, ⅱ) the limited nature and careful management of implicit state, and ⅲ) the ability to avoid parsing large fragments of the message not relevant to a vulnerability. We have built a prototype implementation of our architecture and vulnerability specification language, called VESPA, capable of detecting vulnerabilities in both text and binary protocols. We show that, compared to full protocol parsing, we can achieve 3x or better speedup, and thus detect vulnerabilities in most protocols at a speed of 1 Gbps or more. Our architecture is also well-adapted to being integrated with network processors or other special-purpose hardware. We show that for text protocols, pattern matching dominates our workload and great performance improvements can result from hardware acceleration.
机译:在检测网络攻击时,相比于利用签名,漏洞签名提供了更好的准确性和灵活性。我们表明,通过开发专门针对漏洞签名任务的匹配体系结构,可以在高性能网络入侵检测系统中检测漏洞签名。我们的架构基于:ⅰ)使用高速模式匹配器以及控制逻辑,而不是递归解析;ⅱ)有限的性质和对隐式状态的谨慎管理;ⅲ)避免解析较大片段的能力。该消息与漏洞无关。我们已经构建了称为VESPA的体系结构和漏洞规范语言的原型实现,该语言能够检测文本协议和二进制协议中的漏洞。我们证明,与完整协议解析相比,我们可以实现3倍或更高的速度提升,从而以1 Gbps或更高的速度检测大多数协议中的漏洞。我们的架构也非常适合与网络处理器或其他专用硬件集成。我们证明,对于文本协议,模式匹配在我们的工作量中占主导地位,并且硬件加速可以大大提高性能。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号