Logo del repository
  1. Home
 
Opzioni

Compressing Regular Expression Sets for Deep Packet Inspection

BARTOLI, Alberto
•
CUMAR, SIMONE
•
DE LORENZO, ANDREA
•
MEDVET, Eric
2014
  • conference object

Abstract
The ability to generate security-related alerts while analyzing network traffic in real time has become a key mechanism in many networking devices. This functionality relies on the application of large sets of regular expressions describing attack signatures to each individual packet. Implementing an engine of this form capable of operating at line speed is considerably difficult and the corresponding performance problems have been attacked from several points of view. In this work we propose a novel approach complementing earlier proposals: we suggest transforming the starting set of regular expressions to another set of expressions which is much smaller yet classifies network traffic in the same categories as the starting set. Key component of the transformation is an evolutionary search based on Genetic Programming: a large population of expressions represented as abstract syntax trees evolves by means of mutation and crossover, evolution being driven by fitness indexes tailored to the desired classification needs and which minimize the length of each expression. We assessed our proposals on real datasets composed of up to 474 expressions and the outcome has been very good, resulting in compressions in the order of 74%. Our results are highly encouraging and demonstrate the power of evolutionary techniques in an important application domain.
DOI
10.1007/978-3-319-10762-2_39
WOS
WOS:000358196900039
Archivio
http://hdl.handle.net/11368/2782325
info:eu-repo/semantics/altIdentifier/scopus/2-s2.0-84921709974
Diritti
metadata only access
Soggetti
  • Genetic programming

  • Evolutionary optimiza...

  • Intrusion detection

  • Traffic classificatio...

Scopus© citazioni
4
Data di acquisizione
Jun 7, 2022
Vedi dettagli
google-scholar
Get Involved!
  • Source Code
  • Documentation
  • Slack Channel
Make it your own

DSpace-CRIS can be extensively configured to meet your needs. Decide which information need to be collected and available with fine-grained security. Start updating the theme to match your nstitution's web identity.

Need professional help?

The original creators of DSpace-CRIS at 4Science can take your project to the next level, get in touch!

Realizzato con Software DSpace-CRIS - Estensione mantenuta e ottimizzata da 4Science

  • Impostazioni dei cookie
  • Informativa sulla privacy
  • Accordo con l'utente finale
  • Invia il tuo Feedback