Design and implementation of a high-performance network intrusion prevention system

被引:0
|
作者
Xinidis, K [1 ]
Anagnostakis, KG [1 ]
Markatos, EP [1 ]
机构
[1] Fdn Res & Technol Hellas, Inst Comp Sci, GR-71110 Iraklion, Greece
来源
Security and Privacy in the Age of Ubiquitous Computing | 2005年 / 181卷
关键词
network intrusion detection systems; network intrusion prevention systems; network processors; load balancing;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Network intrusion prevention systems provide proactive defense against security threats by detecting and blocking attack-related traffic. This task can be highly complex, and therefore, software-based network intrusion prevention systems have difficulty in handling high speed links. This paper describes the design and implementation of a high-performance network intrusion prevention system that combines the use of software-based network intrusion AA prevention sensors and a network processor board, The network processor acts as a customized load balancing splitter that cooperates with a set of modified content-based network intrusion detection sensors in processing network traffic. We show that the components of such a system, if co-designed, can achieve high performance, while minimizing redundant processing and communication. We have implemented the system using low-cost, off-the-shelf technology: an IXP1200 network processor evaluation board and commodity PCs. Our evaluation shows that our enhancements can reduce the processing load of the sensors by at least 45% resulting in a system that can handle a fully-loaded Gigabit Ethernet link using at most four commodity PCs.
引用
收藏
页码:359 / 374
页数:16
相关论文
共 50 条
  • [1] Design and implementation of high-performance Intrusion Detection System
    Kim, BK
    Kim, IK
    Kim, KY
    Jang, JS
    COMPUTATIONAL SCIENCE AND ITS APPLICATIONS - ICCSA 2004, PT 4, 2004, 3046 : 594 - 602
  • [2] A high-performance clustering scheme with application in network intrusion prevention system
    Chiu, Chien-Hua
    Lin, Jung-Feng
    Lee, Jiunn-Jye
    Lei, Chin-Laung
    2007 INTERNATIONAL SYMPOSIUM ON COMMUNICATIONS AND INFORMATION TECHNOLOGIES, VOLS 1-3, 2007, : 1219 - 1224
  • [3] Design and implementation of FPGA based high-performance intrusion detection system
    Kim, Byoung-Koo
    Heo, Young-Jun
    Oh, Jin-Tae
    INTELLIGENCE AND SECURITY INFORMATICS, PROCEEDINGS, 2006, 3975 : 724 - 725
  • [4] High-performance Architecture of Network Intrusion Prevention Systems
    Zhao Yueai
    Hou Pengcheng
    Wang Ling
    Han Suqing
    EAI ENDORSED TRANSACTIONS ON SCALABLE INFORMATION SYSTEMS, 2014, 1 (03): : 1 - 5
  • [5] A high-performance network intrusion detection system
    Sekar, R
    Guang, Y
    Verma, S
    Shanbhag, T
    6TH ACM CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY, 1999, : 8 - 17
  • [6] Implementation and performance evaluation of high-performance intrusion detection and response system
    Kim, HJ
    Kim, BK
    Kim, IK
    COMPUTATIONAL SCIENCE AND ITS APPLICATIONS - ICCSA 2004, PT 1, 2004, 3043 : 998 - 1006
  • [7] Research and implementation of a high-performance distributed intrusion detection system
    Yang, Wu
    Fang, Bin-Xing
    Yun, Xiao-Chun
    Zhang, Hong-Li
    Hu, Ming-Zeng
    Beijing Youdian Daxue Xuebao/Journal of Beijing University of Posts and Telecommunications, 2004, 27 (04): : 83 - 86
  • [8] Design of a high-performance network system
    Huang, Liwen
    He, Li
    Jisuanji Gongcheng/Computer Engineering, 2000, 26 (02): : 102 - 103
  • [9] Shunting: A Hardware/Software Architecture for Flexible, High-Performance Network Intrusion Prevention
    Gonzalez, Jose M.
    Paxson, Vern
    Weaver, Nicholas
    CCS'07: PROCEEDINGS OF THE 14TH ACM CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY, 2007, : 139 - 149
  • [10] ASIC Design and Implementation for VoIP Intrusion Prevention System
    Chen, Ming-Jen
    Wen, Chih-Chao
    Lin, Hsin-Chen
    Chu, Yuan-Sun
    PROCEEDINGS OF 2016 INTERNATIONAL CONFERENCE ON APPLIED SYSTEM INNOVATION (ICASI), 2016,