2010Computer Knowledge and TechnologyRequires access

Improvement of Mechanism of Rule-matching in Snort

Jiandong Wang

Open publisher page 0 citations

Abstract

Snort is one kind of packet sniffer based on the libpcap and also it can run as a lightweight network intrusion detection system, which belongs to misuse detection. This paper illustrates Snort's basic principle, system structure, rule analysis, match mechanism and so on. Following that, deficiency in the mechanism of rule-matching is discussed and some improvement opinions and methods are proposed. It aims to speed rule-matching, thus enhance Snort's overall performance.

About this research paper

What this paper is about

Snort is one kind of packet sniffer based on the libpcap and also it can run as a lightweight network intrusion detection system, which belongs to misuse detection. This paper illustrates Snort's basic principle, system structure, rule analysis, match mechanism and so on. Following that, deficiency in the mechanism of rule-matching is discussed and some improvement opinions and methods are proposed. It aims to speed rule-matching, thus enhance Snort's overall performance.

Why it matters

A significance statement is not available in the OpenAlex record.

Key contribution

A contribution statement is not available in the OpenAlex record.

Method / approach

Method details are not available in the OpenAlex metadata.

Main findings

Findings are not separately available in the OpenAlex metadata.

Limitations

Limitations are not available in the OpenAlex metadata.

Applications

Application details are not available in the OpenAlex metadata.

Available abstract

Snort is one kind of packet sniffer based on the libpcap and also it can run as a lightweight network intrusion detection system, which belongs to misuse detection. This paper illustrates Snort's basic principle, system structure, rule analysis, match mechanism and so on. Following that, deficiency in the mechanism of rule-matching is discussed and some improvement opinions and methods are proposed. It aims to speed rule-matching, thus enhance Snort's overall performance.

Key concepts: Computer science, Intrusion detection system, Mechanism (biology), Matching (statistics), Network packet, Rule-based system, Data mining, Real-time computing

Related papers

Back to paper searchBrowse research topicsOriginal source
Improvement of Mechanism of Rule-matching in Snort — Research Paper | ScholarLens