计算机工程与应用 ›› 2012, Vol. 48 ›› Issue (31): 78-81.

• 网络、通信、安全 • 上一篇    下一篇

基于Snort的改进BMH单模式匹配算法研究

燕红文   

  1. 山西农业大学 信息科学与工程学院计科系,山西 太谷 030801
  • 出版日期:2012-11-01 发布日期:2012-10-30

Research on improved BMH single-pattern matching algorithm based on Snort

YAN Hongwen   

  1. School of Information Science and Engineering, Shanxi Agricultural University, Taigu, Shanxi 030801, China
  • Online:2012-11-01 Published:2012-10-30

摘要: 对目前常见的网络入侵检测系统中模式匹配算法进行研究总结,针对著名的Snort中的模式匹配算法,进行了详细分析和对比。基于现存BMH等算法思想,以求取优化检测效率为目标,提出了一种基于Snort的改进BMH模式匹配算法。将改进的BMH模式匹配算法应用到实际网络入侵检测过程中,针对处理结果进行科学评价。通过实例的应用,验证了改进算法的可行性和高效性。

关键词: 网络入侵检测系统, 模式匹配, 单模式, 优化策略

Abstract: This paper researches on the currently common in pattern matching algorithm in network intrusion detection system, carrying out a detailed analysis and comparison of the pattern matching algorithm for famous Snort system. Based on the existed algorithm as BMH, the paper proposes an improved algorithm, seeking optimal effects. The improved BMH pattern matching algorithm in network intrusion detection system is applied to the real network intrusion detection, and the results get scientifically evaluated. Through the practical application, the effectiveness and feasibility of the improved algorithm is shown again.

Key words: network intrusion detection system, pattern matching, single-pattern, optimized strategies