Set-Based Calculation of Topological Relations between Snort Rules

Расчёт топологических отношений между правилами Snort на основе теории множеств
Yi Yin, Naohisa Takahashi, Yun Wang
2014-12-01

Snort rulesalert redundancyintrusion detection systemsset theorytopological relations
Snort is the most popular Intrusion Detection Systems (IDS). It will generate alert messages when an arrival packet matches some of the pre-defined rules. Snort has some problems as follows: it tries the matching for all of the rules even when the packet never matches some rules in case of matching some other rules, and it provides contradictory and redundant alert messages when a set of erroneous and poorly-organized rules is given. This paper proposes a method for characterizing relations between Snort rules towards the solutions for the above problems. The proposed method calculates topological relations between Snort rules based on a set theory.
1
Erroneous or poorly organized Snort rules can produce contradictory and redundant alert messages.
2
Snort may test packets against all predefined rules even when matching one rule makes other rule evaluations unnecessary.
3
The paper proposes characterizing relations between Snort rules to support more efficient matching and reduce conflicting or redundant alerts.
4
Topological relations between Snort rules are calculated using set theory.

Snort rules

topological relations between Snort rules, including their characterization to identify redundant and contradictory rules and avoid unnecessary matching

Publication Details
Publication Date
2014-12-01
Journal
Publisher
ISSN
Access Type
Author Information
Authors
Yi Yin
Naohisa Takahashi
Yun Wang
Explore further
Open the scid.ai AI chat with a ready-made request: it will find papers on a similar topic and help build a literature review.
Find similar papers in the chat
Make a presentation
100%