{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T04:32:06Z","timestamp":1750307526613,"version":"3.41.0"},"reference-count":37,"publisher":"Association for Computing Machinery (ACM)","issue":"4","license":[{"start":{"date-parts":[[2009,8,1]],"date-time":"2009-08-01T00:00:00Z","timestamp":1249084800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Des. Autom. Electron. Syst."],"published-print":{"date-parts":[[2009,8]]},"abstract":"<jats:p>Network Intrusion Detection Systems (NIDS) monitor network traffic to detect attacks or unauthorized activities. Traditional NIDSes search for patterns that match typical network compromise or remote hacking attempts. However, newer networking applications require finding the frequently repeated strings in a packet stream for further investigation of potential attack attempts. Finding frequently repeated strings within a given time frame of the packet stream has been quite efficient to detect polymorphic worm outbreaks. A novel real-time worm outbreak detection system using two-phase hashing and monitoring repeated common substrings is proposed in this article. We use the concept of shared counters to minimize the memory cost while efficiently sifting through suspicious strings. The worm outbreak system has been prototyped on Altera Stratix FPGA. We have tested the system for various settings and packet stream sizes. Experimental results verify that our system can support line speed of gigabit-rates with negligible false positive and negative rates.<\/jats:p>","DOI":"10.1145\/1562514.1562517","type":"journal-article","created":{"date-parts":[[2009,8,25]],"date-time":"2009-08-25T18:02:02Z","timestamp":1251223322000},"page":"1-29","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":3,"title":["A hardware platform for efficient worm outbreak detection"],"prefix":"10.1145","volume":"14","author":[{"given":"Miad","family":"Faezipour","sequence":"first","affiliation":[{"name":"The University of Texas at Dallas, Richardson, Texas"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Mehrdad","family":"Nourani","sequence":"additional","affiliation":[{"name":"The University of Texas at Dallas, Richardson, Texas"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Rina","family":"Panigrahy","sequence":"additional","affiliation":[{"name":"Microsoft Research Lab, Mountain View, CA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2009,8,28]]},"reference":[{"key":"e_1_2_1_1_1","volume-title":"Proceedings of the IEEE International Conference on Communications (ICC'05)","volume":"2","author":"Akritidis P.","unstructured":"Akritidis , P. , Anagnostakis , K. , and Markatos , E. P . 2005. Efficient content-based detection of zero-day worms . In Proceedings of the IEEE International Conference on Communications (ICC'05) , vol. 2 . IEEE, 837--843. Akritidis, P., Anagnostakis, K., and Markatos, E. P. 2005. Efficient content-based detection of zero-day worms. In Proceedings of the IEEE International Conference on Communications (ICC'05), vol. 2. IEEE, 837--843."},{"key":"e_1_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1145\/974044.974078"},{"key":"e_1_2_1_3_1","unstructured":"Barford P. 2008. Network traffic. http:\/\/pages.cs.wisc.edu\/~pb\/640\/traffic.ppt.  Barford P. 2008. Network traffic. http:\/\/pages.cs.wisc.edu\/~pb\/640\/traffic.ppt."},{"key":"e_1_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1145\/362686.362692"},{"key":"e_1_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1016\/S0304-3975(03)00400-6"},{"key":"e_1_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1145\/1102120.1102152"},{"key":"e_1_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1145\/1015467.1015495"},{"key":"e_1_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1145\/633025.633056"},{"key":"e_1_2_1_9_1","volume-title":"Ethereal: A networking protocol analyzer. www.ethereal.com.","author":"Ethereal","year":"2007","unstructured":"Ethereal . 2007 . Ethereal: A networking protocol analyzer. www.ethereal.com. Ethereal. 2007. Ethereal: A networking protocol analyzer. www.ethereal.com."},{"key":"e_1_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1109\/HOTI.2007.6"},{"key":"e_1_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1145\/276304.276334"},{"key":"e_1_2_1_12_1","unstructured":"Idika N. and Mathur A. P. 2007. A survey of malware detection techniques. Tech. rep Purdue University.  Idika N. and Mathur A. P. 2007. A survey of malware detection techniques. Tech. rep Purdue University."},{"key":"e_1_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACSAC.2006.35"},{"key":"e_1_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1145\/1080173.1080176"},{"volume-title":"Proceedings of 13th USENIX Security Symposium, 271--286","author":"Kim H. A.","key":"e_1_2_1_15_1","unstructured":"Kim , H. A. and Karp , B . 2004. Autograph: Toward automated, distributed worm signature detection . In Proceedings of 13th USENIX Security Symposium, 271--286 . Kim, H. A. and Karp, B. 2004. Autograph: Toward automated, distributed worm signature detection. In Proceedings of 13th USENIX Security Symposium, 271--286."},{"key":"e_1_2_1_16_1","unstructured":"Kolesnikov O. and Lee W. 2005. Advanced polymorphic worms: Evading ids by blending in with normal traffic. Tech. rep. Georgia Institute of Technology.  Kolesnikov O. and Lee W. 2005. Advanced polymorphic worms: Evading ids by blending in with normal traffic. Tech. rep. Georgia Institute of Technology."},{"key":"e_1_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1145\/1028788.1028812"},{"key":"e_1_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1109\/CONECT.2004.1375207"},{"key":"e_1_2_1_19_1","unstructured":"Moore D. Paxson V. Savage S. Shannon C. Staniford S. and Weaver N. 2003. The spread of the sapphire\/slammer worm. http:\/\/www.caida.org\/publications\/papers\/2003\/sapphire\/sapphire.html.  Moore D. Paxson V. Savage S. Shannon C. Staniford S. and Weaver N. 2003. The spread of the sapphire\/slammer worm. http:\/\/www.caida.org\/publications\/papers\/2003\/sapphire\/sapphire.html."},{"key":"e_1_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2005.15"},{"volume-title":"User Manuals for Nios II Ide Version 6.0 Toolset","key":"e_1_2_1_21_1","unstructured":"NIOS. 2006. User Manuals for Nios II Ide Version 6.0 Toolset . ALTERA Corp . NIOS. 2006. User Manuals for Nios II Ide Version 6.0 Toolset. ALTERA Corp."},{"volume-title":"User manuals for quartus II Version 6.0 Toolset","author":"Quartus","key":"e_1_2_1_22_1","unstructured":"Quartus . 2006. User manuals for quartus II Version 6.0 Toolset . ALTERA Corp . Quartus. 2006. User manuals for quartus II Version 6.0 Toolset. ALTERA Corp."},{"key":"e_1_2_1_23_1","unstructured":"SANS. 2009. Malware faq: Code-red-iss buffer overflow. http:\/\/www.sans.org\/resources\/malwarefaq\/code-red.php.  SANS. 2009. Malware faq: Code-red-iss buffer overflow. http:\/\/www.sans.org\/resources\/malwarefaq\/code-red.php."},{"key":"e_1_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1145\/872757.872770"},{"volume-title":"http:\/\/theory.cs.uvic.ca\/gen\/poly.html","author":"Server O.","key":"e_1_2_1_25_1","unstructured":"Server , O. 2006. Polynomials . http:\/\/theory.cs.uvic.ca\/gen\/poly.html . University of Victoria . Server, O. 2006. Polynomials. http:\/\/theory.cs.uvic.ca\/gen\/poly.html. University of Victoria."},{"volume-title":"Proceedings of the ACM Symposium on Operating System Design and Implementation (OSDI'04)","author":"Singh S.","key":"e_1_2_1_26_1","unstructured":"Singh , S. , Estan , C. , Varghese , G. , and Savage , S . 2004. Automated worm fingerprinting . In Proceedings of the ACM Symposium on Operating System Design and Implementation (OSDI'04) . ACM, 45--60. Singh, S., Estan, C., Varghese, G., and Savage, S. 2004. Automated worm fingerprinting. In Proceedings of the ACM Symposium on Operating System Design and Implementation (OSDI'04). ACM, 45--60."},{"key":"e_1_2_1_27_1","unstructured":"SNORT. 2007. Snort network intrusion detection system. www.snort.org.  SNORT. 2007. Snort network intrusion detection system. www.snort.org."},{"key":"e_1_2_1_28_1","unstructured":"Song D. Malan R. and Stone R. 2001. A snapshot of global internet worm activity. Tech. rep. Arbor Networks.  Song D. Malan R. and Stone R. 2001. A snapshot of global internet worm activity. Tech. rep. Arbor Networks."},{"volume-title":"Proceedings of the IEEE Global Telecommunications Conference (GLOBECOM'05)","author":"Song H.","key":"e_1_2_1_29_1","unstructured":"Song , H. and Lockwood , J. W . 2005. Multi-pattern signature matching for hardware network intrusion detection systems . In Proceedings of the IEEE Global Telecommunications Conference (GLOBECOM'05) . IEEE, 1686--1690. Song, H. and Lockwood, J. W. 2005. Multi-pattern signature matching for hardware network intrusion detection systems. In Proceedings of the IEEE Global Telecommunications Conference (GLOBECOM'05). IEEE, 1686--1690."},{"key":"e_1_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1145\/1029618.1029624"},{"key":"e_1_2_1_31_1","volume-title":"User Manuals for Synopsys Toolset Version","author":"Synopsys","year":"2005","unstructured":"Synopsys . 2005. User Manuals for Synopsys Toolset Version 2005 .06. Synopsys Inc . Synopsys. 2005. User Manuals for Synopsys Toolset Version 2005.06. Synopsys Inc."},{"key":"e_1_2_1_32_1","volume-title":"NANOG26 Meeting, http:\/\/www.nanog.org\/mtg-0210\/ppt\/telkamp.pdf.","author":"Telkamp T.","year":"2002","unstructured":"Telkamp , T. 2002 . Traffic characteristics and network planning . NANOG26 Meeting, http:\/\/www.nanog.org\/mtg-0210\/ppt\/telkamp.pdf. Telkamp, T. 2002. Traffic characteristics and network planning. NANOG26 Meeting, http:\/\/www.nanog.org\/mtg-0210\/ppt\/telkamp.pdf."},{"volume-title":"Proceedings of the 7th International Symposium on Recent Advances in Intrusion Detection (RAID04)","author":"Wang K.","key":"e_1_2_1_33_1","unstructured":"Wang , K. , Cretu , G. , and Stolfo , S. J . 2004. Anomalous payload-based network intrusion detection . In Proceedings of the 7th International Symposium on Recent Advances in Intrusion Detection (RAID04) . Wang, K., Cretu, G., and Stolfo, S. J. 2004. Anomalous payload-based network intrusion detection. In Proceedings of the 7th International Symposium on Recent Advances in Intrusion Detection (RAID04)."},{"key":"e_1_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.5555\/784592.784785"},{"volume-title":"Proceedings of the 12th IEEE International Conference on Network Protocols Symposium on High-Performance Interconnects (ICNP'04)","author":"Yu F.","key":"e_1_2_1_35_1","unstructured":"Yu , F. , Katz , R. H. , and Lakshman , T. V . 2004. Gigabit rate packet pattern-matching using tcam . In Proceedings of the 12th IEEE International Conference on Network Protocols Symposium on High-Performance Interconnects (ICNP'04) . IEEE, 174--183. Yu, F., Katz, R. H., and Lakshman, T. V. 2004. Gigabit rate packet pattern-matching using tcam. In Proceedings of the 12th IEEE International Conference on Network Protocols Symposium on High-Performance Interconnects (ICNP'04). IEEE, 174--183."},{"key":"e_1_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1145\/586110.586130"},{"key":"e_1_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1109\/JSAC.2006.877137"}],"container-title":["ACM Transactions on Design Automation of Electronic Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1562514.1562517","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/1562514.1562517","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T12:23:04Z","timestamp":1750249384000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1562514.1562517"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2009,8]]},"references-count":37,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2009,8]]}},"alternative-id":["10.1145\/1562514.1562517"],"URL":"https:\/\/doi.org\/10.1145\/1562514.1562517","relation":{},"ISSN":["1084-4309","1557-7309"],"issn-type":[{"type":"print","value":"1084-4309"},{"type":"electronic","value":"1557-7309"}],"subject":[],"published":{"date-parts":[[2009,8]]},"assertion":[{"value":"2007-09-01","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2009-06-01","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2009-08-28","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}