FINDING · DEFENSE
LibFTE's NFA-based 'relaxed ranking' sidesteps the PSPACE-hardness obstacle that previously made direct NFA ranking unworkable. Across 3,458 Snort IDS regular expressions in the network-monitor-circumvention setting, NFA-based ranking reduces client/server memory requirements by as much as 30% compared to DFA-based approaches.
From 2014-luchaup-libfte — LibFTE: A Toolkit for Constructing Practical, Format-Abiding Encryption Schemes · §1, §4.1 · 2014 · USENIX Security Symposium
Implications
- Prefer NFA-based FTE implementations over DFA-based ones when deploying format-transforming pluggable transports, especially on memory-constrained clients such as mobile devices.
- Use an automated configuration assistant (as in libfte) to select NFA vs. DFA ranking based on per-format memory thresholds rather than hard-coding DFA conversion.
Tags
Extracted by claude-sonnet-4-6 — review before relying.