A Parallel Architecture for Stateful, High-Speed Intrusion Detection

被引:0
作者
Foschini, Luca [1 ]
Thapliyal, Ashish V. [1 ]
Cavallaro, Lorenzo [1 ]
Kruegel, Christopher [1 ]
Vigna, Giovanni [1 ]
机构
[1] Univ Calif Santa Barbara, Dept Comp Sci, Santa Barbara, CA 93106 USA
来源
INFORMATION SYSTEMS SECURITY, PROCEEDINGS | 2008年 / 5352卷
关键词
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The increase in bandwidth over processing power has made stateful intrusion detection for high-speed networks snore difficult,, and, in certain cases, impossible. The problem of real-time stateful intrusion detection in high-speed networks cannot easily be solved by optimizing the packet; matching algorithm utilized by a, centralized process or by using custom-developed hardware. Instead, there is a need for a parallel approach that is able to decompose the problem into subproblems of manageable size. We present a novel parallel matching algorithm for the signature-based detection of network attacks. The algorithm is able to perform stateful signature matching and has been implemented only using off-the-shelf components. Our initial experiments confirm that, by making the rule snatching process parallel, it is possible to achieve a, scalable implementation of a stateful, network-based intrusion detection system.
引用
收藏
页码:203 / 220
页数:18
相关论文
共 22 条
  • [1] Amdahl G. M., 1967, P AFIPS C
  • [2] [Anonymous], 2004, OP SOURC NETW INTR D
  • [3] [Anonymous], OPEN SOURCE COMMUNIT
  • [4] COLAJANNI M, 2006, PARALLEL ARCHITECTUR
  • [5] DAVOLI R, 2004, VIRTUAL DISTRIBUTED
  • [6] DAVOLI R, 2005, TRIDENTCOM 05, P213, DOI DOI 10.1109/TRIDNT.2005.38
  • [7] Eckmann S. T., 2000, P ACM WORKSH INTR DE
  • [8] FOSCHINI L, 2007, FORMALIZATION ANAL H
  • [9] FOSCHINI L, 2008, PARALLEL ARCHITECTUR
  • [10] Garcia-Molina H, 1982, IEEE T COMPUTERS