Skip to Main Content
Pattern matching is an important detecting method of a misuse intrusion detection system. With the increase in the number of rules, the performance of pattern matching algorithm has been a gradually decline and has been a bottleneck. A new type of pattern matching based on suffix tree is proposed. The method mines rule's data structure and prunes rule set based suffix tree, the model size of the search space has been reduced. Experiments show, compared to the conventional pattern matching method, it is an effective method to reduce the time of pattern matching, and improves the detection efficiency of intrusion detection systems.