Result Details

Approximate Reduction of Finite Automata for High-Speed Network Intrusion Detection

ČEŠKA, M.; HAVLENA, V.; HOLÍK, L.; LENGÁL, O.; VOJNAR, T. Approximate Reduction of Finite Automata for High-Speed Network Intrusion Detection. International Journal on Software Tools for Technology Transfer, 2020, vol. 22, no. 5, p. 523-539. ISSN: 1433-2779.
Type
journal article
Language
English
Authors
Abstract

We consider the problem of approximate reduction of non-deterministic automata that appear in hardware-accelerated network intrusion detection systems (NIDSes). We define an error distance of a reduced automaton from the original one as the probability of packets being incorrectly classified by the reduced automaton (wrt the probabilistic distribution of packets in the network traffic). We use this notion to design an approximate reduction procedure that achieves a great size reduction (much beyond the state-of-the-art language-preserving techniques) with a controlled and small error. We have implemented our approach and evaluated it on use cases from Snort, a popular NIDS. Our results provide experimental evidence that the method can be highly efficient in practice, allowing NIDSes to follow the rapid growth in the speed of networks.

Keywords

reduction, nondeterministic finite automata, deep packet inspection, high-speed network monitoring 

URL
Published
2020
Pages
523–539
Journal
International Journal on Software Tools for Technology Transfer, vol. 22, no. 5, ISSN 1433-2779
DOI
UT WoS
000573269500001
EID Scopus
BibTeX
@article{BUT161576,
  author="Milan {Češka} and Vojtěch {Havlena} and Lukáš {Holík} and Ondřej {Lengál} and Tomáš {Vojnar}",
  title="Approximate Reduction of Finite Automata for High-Speed Network Intrusion Detection",
  journal="International Journal on Software Tools for Technology Transfer",
  year="2020",
  volume="22",
  number="5",
  pages="523--539",
  doi="10.1007/s10009-019-00520-8",
  issn="1433-2779",
  url="https://link.springer.com/article/10.1007/s10009-019-00520-8"
}
Files
Projects
Bezpečné a spolehlivé počítačové systémy, BUT, Vnitřní projekty VUT, FIT-S-17-4014, start: 2017-03-01, end: 2020-02-29, completed
Efficient Automata Techniques for Formal Reasoning, GACR, Juniorské granty, GJ16-24707Y, start: 2016-01-01, end: 2018-12-31, completed
IT4Innovations excellence in science, MŠMT, Národní program udržitelnosti II, LQ1602, start: 2016-01-01, end: 2020-12-31, completed
Research groups
Departments
Back to top