Snort Rule Set Structure Method Based on Frequency

ZHOU Yu,TAN Xiao-bin,HE Xian-zong,XI Hong-sheng
DOI: https://doi.org/10.3969/j.issn.1000-3428.2010.12.053
2010-01-01
Abstract:A method of establishing rule set of snort based on frequency is proposed to enhance the efficiency of rule matching of snort intrusion detection system.Snort system analyzes network packets using rule set to find intrusion behaviors.A method is proposed which creates rule trees by the principle of low frequency first matching after calculating the frequency of each packets option,to decrease matching times and raise efficiency.By analysis of experimentation,it is proved that method based on frequency combined with parameter set archives excellent effects and enhances matching efficiency compared with Snort2 method.
What problem does this paper attempt to address?