Efficient Wu-Manber Pattern Matching Hardware for Intrusion and Malware Detection

03/01/2020
by   Monther Aldwairi, et al.
0

Network intrusion detection systems and antivirus software are essential in detecting malicious network traffic and attacks such as denial-of-service and malwares. Each attack, worm or virus has its own distinctive signature. Signature-based intrusion detection and antivirus systems depend on pattern matching to look for possible attack signatures. Pattern matching is a very complex task, which requires a lot of time, memory and computing resources. Software-based intrusion detection is not fast enough to match high network speeds and the increasing number of attacks. In this paper, we propose special purpose hardware for Wu-Manber pattern matching algorithm. FPGAs form an excellent choice because of their massively parallel structure, reprogrammable logic and memory resources. The hardware is designed in Verilog and implemented using Xilinx ISE. For evaluation, we dope network traffic traces collected using Wireshark with 2500 signatures from the ClamAV virus definitions database. Experimental results show high speed that reaches up to 216 Mbps. In addition, we evaluate time, device usage, and power consumption.

READ FULL TEXT
research
06/09/2018

A Taxonomy of Malicious Traffic for Intrusion Detection Systems

With the increasing number of network threats it is essential to have a ...
research
07/09/2018

Recurrent Neural Networks for Enhancement of Signature-based Network Intrusion Detection Systems

Security of information passing through the Internet is threatened by to...
research
05/28/2018

Identification of Flaws in the Design of Signatures for Intrusion Detection Systems

Signature-based Intrusion Detection System (SIDS) provides a promising s...
research
08/06/2019

A Public Network Trace of a Control and Automation System

The increasing number of attacks against automation systems such as SCAD...
research
03/05/2010

Integrating Innate and Adaptive Immunity for Intrusion Detection

Network Intrusion Detection Systems (NDIS) monitor a network with the ai...
research
04/20/2022

ARLIF-IDS – Attention augmented Real-Time Isolation Forest Intrusion Detection System

Distributed Denial of Service (DDoS) attack is a malicious attempt to di...
research
05/01/2019

On the Convergence Rates of Learning-based Signature Generation Schemes to Contain Self-propagating Malware

In this paper, we investigate the importance of a defense system's learn...

Please sign up or login with your details

Forgot password? Click here to reset