DPFEE: A High Performance Scalable Pre-processor for Network Security Systems

Home / Publications / DPFEE: A High Performance Scalable Pre-processor for Network Security Systems

Vinayaka Jyothi, Sateesh K. Addepalli and Ramesh Karri

Network Intrusion Detection Systems (NIDS) and Anti-Denial-of-Service (DoS) employ Deep Packet Inspection (DPI) which provides visibility to the content of payload to detect network attacks. All DPI engines assume a pre-processing step that extracts the various protocol-specific fields. However, application layer (L7) field extraction is computationally expensive. We propose a novel Deep Packet Field Extraction Engine (DPFEE) for application layer field extraction to hardware. DPFEE is a content-aware, grammar-based, Layer 7 programmable field extraction engine for text-based protocols.