Packet payload monitoring for internet worm content detection using deterministic finite automaton with delayed dictionary compression

4Citations
Citations of this article
11Readers
Mendeley users who have this article in their library.

Abstract

Packet content scanning is one of the crucial threats to network security and network monitoring applications. In monitoring applications, payload of packets in a network is matched against the set of patterns in order to detect attacks like worms, viruses, and protocol definitions. During network transfer, incoming and outgoing packets are monitored in depth to inspect the packet payload. In this paper, the regular expressions that are basically string patterns are analyzed for packet payloads in detecting worms. Then the grouping scheme for regular expression matching is rewritten using Deterministic Finite Automaton (DFA). DFA achieves better processing speed during regular expression matching. DFA requires more memory space for each state. In order to reduce memory utilization, decompression technique is used. Delayed Dictionary Compression (DDC) is applied for achieving better speeds in the communication links. DDC achieves decoding latency during compression of payload packets in the network. Experimental results show that the proposed approach provides better time consumption and memory utilization during detection of Internet worm attacks.

References Powered by Scopus

Anomalous payload-based network intrusion detection

438Citations
N/AReaders
Get full text

The spread of the Witty worm

225Citations
N/AReaders
Get full text

Pre-decoded CAMs for efficient and high-speed NIDS pattern matching

188Citations
N/AReaders
Get full text

Cited by Powered by Scopus

Economic dimensions of blockchain technology: In the context of extention of cryptocurrencies

25Citations
N/AReaders
Get full text

FPGA-Assisted DPI Systems: 100 Gbit/s and Beyond

12Citations
N/AReaders
Get full text

Mobile malware detection using anomaly based machine learning classifier techniques

5Citations
N/AReaders
Get full text

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Cite

CITATION STYLE

APA

Selvaraj, D., & Ganapathi, P. (2014). Packet payload monitoring for internet worm content detection using deterministic finite automaton with delayed dictionary compression. Journal of Computer Networks and Communications, 2014. https://doi.org/10.1155/2014/206867

Readers' Seniority

Tooltip

PhD / Post grad / Masters / Doc 2

67%

Professor / Associate Prof. 1

33%

Readers' Discipline

Tooltip

Computer Science 2

40%

Engineering 2

40%

Social Sciences 1

20%

Save time finding and organizing research with Mendeley

Sign up for free