Detail výsledku

Approximate Reduction of Finite Automata for High-Speed Network Intrusion Detection

ČEŠKA, M.; HAVLENA, V.; HOLÍK, L.; LENGÁL, O.; VOJNAR, T. Approximate Reduction of Finite Automata for High-Speed Network Intrusion Detection. In Proceedings of TACAS'18. Lecture Notes in Computer Science. Thessaloniki: Springer Verlag, 2018. no. 2, p. 155-175. ISSN: 0302-9743.
Typ
článek ve sborníku konference
Jazyk
anglicky
Autoři
Abstrakt

We consider the problem of approximate reduction of non-deterministic automata that appear in hardware-accelerated network intrusion detection systems (NIDSes). We define an error distance of a reduced automaton from the original one as the probability of packets being incorrectly classified by the reduced automaton (wrt the probabilistic distribution of packets in the network traffic). We use this notion to design an approximate reduction procedure that achieves a great size reduction (much beyond the state-of-the-art language preserving techniques) with a controlled and small error. We have implemented our approach and evaluated it on use cases from Snort , a popular NIDS. Our results provide experimental evidence that the method can be highly efficient in practice, allowing NIDSes to follow the rapid growth in the speed of networks.

Klíčová slova


approximate reduction, probabilistic distance, finite automata, probabilistic automaton, network intrusion detection

Rok
2018
Strany
155–175
Časopis
Lecture Notes in Computer Science, roč. 10806, č. 2, ISSN 0302-9743
Sborník
Proceedings of TACAS'18
Konference
European Joint Conferences on Theory and Practice of Software
Vydavatel
Springer Verlag
Místo
Thessaloniki
DOI
UT WoS
000445822600009
EID Scopus
BibTeX
@inproceedings{BUT147192,
  author="Milan {Češka} and Vojtěch {Havlena} and Lukáš {Holík} and Ondřej {Lengál} and Tomáš {Vojnar}",
  title="Approximate Reduction of Finite Automata for High-Speed Network Intrusion Detection",
  booktitle="Proceedings of TACAS'18",
  year="2018",
  journal="Lecture Notes in Computer Science",
  volume="10806",
  number="2",
  pages="155--175",
  publisher="Springer Verlag",
  address="Thessaloniki",
  doi="10.1007/978-3-319-89963-3\{_}9",
  issn="0302-9743",
  url="https://www.fit.vut.cz/research/publication/11657/"
}
Soubory
Projekty
Bezpečné a spolehlivé počítačové systémy, VUT, Vnitřní projekty VUT, FIT-S-17-4014, zahájení: 2017-03-01, ukončení: 2020-02-29, ukončen
IT4Innovations excellence in science, MŠMT, Národní program udržitelnosti II, LQ1602, zahájení: 2016-01-01, ukončení: 2020-12-31, ukončen
Přibližná ekvivalence pro aproximativní počítání, GAČR, Standardní projekty, GA16-17538S, zahájení: 2016-01-01, ukončení: 2018-12-31, ukončen
Výzkumné skupiny
Pracoviště
Nahoru