{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T04:56:32Z","timestamp":1750308992100,"version":"3.41.0"},"reference-count":32,"publisher":"Association for Computing Machinery (ACM)","issue":"3","license":[{"start":{"date-parts":[[2007,6,1]],"date-time":"2007-06-01T00:00:00Z","timestamp":1180656000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["SIGARCH Comput. Archit. News"],"published-print":{"date-parts":[[2007,6]]},"abstract":"<jats:p>While string matching plays an important role in deep packet inspection applications, its software algorithms are insufficient to meet the demands of high-speed performance. Accordingly, we were motivated to propose fast and deterministic performance root-hashing automaton matching (RHAM) coprocessor for embedded network processor. Although automaton algorithms are robust with deterministic matching time, there is still plenty of room for improvement of their average-case performance. The proposed RHAM employs novel root-hashing technique to accelerate automaton matching. In our experiment, RHAM is implemented in a prevalent automaton algorithm, Aho-Corasick (AC) which is often used in many packet inspection applications. Compared to the original AC, RHAM only requires extra vector size in 48 Kbytes for root-hashing, and has about 900% and 420% outperformance for 20,000 URLs and 10,000 virus patterns respectively. Implementaion of RHAM FPGA can perform at the rate of 12.6 Gbps with the pattern amount in 34,215 bytes. This is superior to all previous matching hardware in terms of throughput and pattern set.<\/jats:p>","DOI":"10.1145\/1294313.1294314","type":"journal-article","created":{"date-parts":[[2007,10,12]],"date-time":"2007-10-12T15:47:29Z","timestamp":1192204049000},"page":"36-43","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":5,"title":["Deterministic high-speed root-hashing automaton matching coprocessor for embedded network processor"],"prefix":"10.1145","volume":"35","author":[{"given":"Kuo-Kun","family":"Tseng","sequence":"first","affiliation":[{"name":"National Chiao Tung University, Taiwan"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ying-Dar","family":"Lin","sequence":"additional","affiliation":[{"name":"National Chiao Tung University, Taiwan"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Tsern-Huei","family":"Lee","sequence":"additional","affiliation":[{"name":"National Chiao Tung University, Taiwan"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yuan-Cheng","family":"Lai","sequence":"additional","affiliation":[{"name":"National Taiwan University of Science and Technology, Taiwan"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2007,6]]},"reference":[{"key":"e_1_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1145\/974044.974078"},{"key":"e_1_2_1_3_1","unstructured":"M. Roesch etal \"Snort: The Open Source Network Intrusion Detection System \" http:\/\/www.snort.org\/.  M. Roesch et al \"Snort: The Open Source Network Intrusion Detection System \" http:\/\/www.snort.org\/ ."},{"key":"e_1_2_1_4_1","unstructured":"T. Kojm etal \"Clam Anti-virus \" http:\/\/www.clamav.net\/.  T. Kojm et al \"Clam Anti-virus \" http:\/\/www.clamav.net\/."},{"key":"e_1_2_1_5_1","unstructured":"J. Mason etal The Apache SpamAssassin Project. http:\/\/spamassassin.apache.org\/.  J. Mason et al The Apache SpamAssassin Project. http:\/\/spamassassin.apache.org\/."},{"key":"e_1_2_1_6_1","unstructured":"T. D. Internordia etal \"SquidGuard filter \" http:\/\/www.squidguard.org\/.  T. D. Internordia et al \"SquidGuard filter \" http:\/\/www.squidguard.org\/ ."},{"key":"e_1_2_1_7_1","unstructured":"D. Barron etal \"DansGuardian content filter \" http:\/\/dansguardian.org\/.  D. Barron et al \"DansGuardian content filter \" http:\/\/dansguardian.org\/ ."},{"key":"e_1_2_1_8_1","doi-asserted-by":"crossref","unstructured":"G. Navarro and M. Ranot \"Flexible Pattern Matching in Strings \" Cambridge University Press 2002.   G. Navarro and M. Ranot \"Flexible Pattern Matching in Strings \" Cambridge University Press 2002.","DOI":"10.1017\/CBO9781316135228"},{"key":"e_1_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1145\/375360.375365"},{"key":"e_1_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1145\/135239.135244"},{"key":"e_1_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1145\/359842.359859"},{"key":"e_1_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1145\/360825.360855"},{"volume-title":"Hong Kong","year":"2004","author":"Tuck N.","key":"e_1_2_1_13_1"},{"key":"e_1_2_1_14_1","first-page":"367","author":"Coit C.","year":"2002","journal-title":"\"Towards Faster String Matching for Intrusion Detection,\" DARPA Information Survivability Conference and Exhibition"},{"key":"e_1_2_1_15_1","unstructured":"N. Desai \"Increasing performance in high speed NIDS \" http:\/\/www.snort.org\/.  N. Desai \"Increasing performance in high speed NIDS \" http:\/\/www.snort.org\/ ."},{"volume-title":"Workshop on String Processing, Carleton U. Press","year":"1997","author":"Raffinot M.","key":"e_1_2_1_16_1"},{"key":"e_1_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1109\/ISCA.2005.5"},{"key":"e_1_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1109\/MM.2004.1268997"},{"key":"e_1_2_1_19_1","unstructured":"I. Sourdis D. Pnevmatikatos S. Wong and S. Vassiliadis \"A reconfigurable perfect-hashing scheme for packet inspection \" International Conference on Field Programmable Logic and Applications Aug. 2005.  I. Sourdis D. Pnevmatikatos S. Wong and S. Vassiliadis \"A reconfigurable perfect-hashing scheme for packet inspection \" International Conference on Field Programmable Logic and Applications Aug. 2005."},{"key":"e_1_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1145\/1055626.1055640"},{"key":"e_1_2_1_21_1","unstructured":"J. Lockwood \"An Open Platform for Development of Network Processing Modules in Reconfigurable Hardware \" IEC DesignCon Santa Clara CA Jan. 2001.  J. Lockwood \"An Open Platform for Development of Network Processing Modules in Reconfigurable Hardware \" IEC DesignCon Santa Clara CA Jan. 2001."},{"key":"e_1_2_1_22_1","unstructured":"J. Moscola J. Lockwood R. P. Loui and M. Pachos \"Implementation of a Content-Scanning Module for an Internet Firewall \" IEEE FCCM 2003.   J. Moscola J. Lockwood R. P. Loui and M. Pachos \"Implementation of a Content-Scanning Module for an Internet Firewall \" IEEE FCCM 2003."},{"key":"e_1_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1145\/968280.968312"},{"key":"e_1_2_1_24_1","unstructured":"G. Tripp \"A Finite-State-Machine Based String Matching System for Intrusion Detection on High-Speed Network. \" EICAR May 2005.  G. Tripp \"A Finite-State-Machine Based String Matching System for Intrusion Detection on High-Speed Network. \" EICAR May 2005."},{"key":"e_1_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1145\/988952.989042"},{"key":"e_1_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1109\/FCCM.2001.22"},{"volume-title":"CA","year":"2002","author":"Franklin R.","key":"e_1_2_1_27_1"},{"key":"e_1_2_1_28_1","unstructured":"C. R. Clark and D. E. Schimmel \"Scalable Pattern Matching for High Speed Networks \" IEEE FCCM 2004.   C. R. Clark and D. E. Schimmel \"Scalable Pattern Matching for High Speed Networks \" IEEE FCCM 2004."},{"key":"e_1_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1145\/1065579.1065641"},{"key":"e_1_2_1_30_1","unstructured":"I. Sourdis and D. Pnevmatikatos \"Pre-Decoded CAMs for Efficient and High-Speed NIDS Pattern Matching \" IEEE FCCM 2004.   I. Sourdis and D. Pnevmatikatos \"Pre-Decoded CAMs for Efficient and High-Speed NIDS Pattern Matching \" IEEE FCCM 2004."},{"key":"e_1_2_1_31_1","doi-asserted-by":"crossref","unstructured":"M. Gokhale D. Dubois A. Dubois M. Boorman S. Poole and V. Hogsett \"Granidt: Towards Gigabit Rate Network Intrusion Detection Technology \" LNCS Volume 2438 Jan 2002.   M. Gokhale D. Dubois A. Dubois M. Boorman S. Poole and V. Hogsett \"Granidt: Towards Gigabit Rate Network Intrusion Detection Technology \" LNCS Volume 2438 Jan 2002.","DOI":"10.1007\/3-540-46117-5_43"},{"key":"e_1_2_1_32_1","unstructured":"H. M. Bl\u00fcthgen T. Noll and R. Aachen \"A Programmable Processor For Approximate String Matching With High Throughput Rate \" IEEE ASAP 2000.  H. M. Bl\u00fcthgen T. Noll and R. Aachen \"A Programmable Processor For Approximate String Matching With High Throughput Rate \" IEEE ASAP 2000."},{"volume-title":"Hawaii","year":"1999","author":"Park J. H.","key":"e_1_2_1_33_1"}],"container-title":["ACM SIGARCH Computer Architecture News"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1294313.1294314","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/1294313.1294314","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T21:41:18Z","timestamp":1750282878000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1294313.1294314"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2007,6]]},"references-count":32,"journal-issue":{"issue":"3","published-print":{"date-parts":[[2007,6]]}},"alternative-id":["10.1145\/1294313.1294314"],"URL":"https:\/\/doi.org\/10.1145\/1294313.1294314","relation":{},"ISSN":["0163-5964"],"issn-type":[{"type":"print","value":"0163-5964"}],"subject":[],"published":{"date-parts":[[2007,6]]},"assertion":[{"value":"2007-06-01","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}