Improvement of Mechanism of Rule-matching in Snort
Jiandong Wang
Abstract
Jiandong Wang
Abstract
Snort is one kind of packet sniffer based on the libpcap and also it can run as a lightweight network intrusion detection system, which belongs to misuse detection. This paper illustrates Snort's basic principle, system structure, rule analysis, match mechanism and so on. Following that, deficiency in the mechanism of rule-matching is discussed and some improvement opinions and methods are proposed. It aims to speed rule-matching, thus enhance Snort's overall performance.
A significance statement is not available in the OpenAlex record.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
Snort is one kind of packet sniffer based on the libpcap and also it can run as a lightweight network intrusion detection system, which belongs to misuse detection. This paper illustrates Snort's basic principle, system structure, rule analysis, match mechanism and so on. Following that, deficiency in the mechanism of rule-matching is discussed and some improvement opinions and methods are proposed. It aims to speed rule-matching, thus enhance Snort's overall performance.
Key concepts: Computer science, Intrusion detection system, Mechanism (biology), Matching (statistics), Network packet, Rule-based system, Data mining, Real-time computing