论文部分内容阅读
检测引擎是入侵检测系统关键部件,模式匹配算法则是检测引擎的核心。本文在分析了著名的多模式匹配算法Wu-Manber算法的基础上,对该算法在Snort中的实现(MWM算法)及对影响算法性能的因素进行了分析。通过实验验证了最短模式长度对算法的性能有着较大的影响。提出了改进方案,通过拆分模式集,改变模式集中最短模式的长度,以更好的发挥MWM算法的优势,从而提高入侵检测的效率。
Detection engine is a key component of intrusion detection system, and pattern matching algorithm is the core of detection engine. Based on the analysis of Wu-Manber algorithm, a well-known multi-pattern matching algorithm, this paper analyzes the algorithm’s implementation in Snort (MWM algorithm) and its influence on the performance of the algorithm. Experiments show that the shortest mode length has a great influence on the performance of the algorithm. An improved scheme is proposed. By splitting the pattern set, the length of the shortest pattern in the pattern set can be changed to take advantage of the MWM algorithm and improve the efficiency of intrusion detection.