A Parallel Architecture for Stateful, High-Speed Intrusion Detection

被引:0
|
作者
Foschini, Luca [1 ]
Thapliyal, Ashish V. [1 ]
Cavallaro, Lorenzo [1 ]
Kruegel, Christopher [1 ]
Vigna, Giovanni [1 ]
机构
[1] Univ Calif Santa Barbara, Dept Comp Sci, Santa Barbara, CA 93106 USA
来源
关键词
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The increase in bandwidth over processing power has made stateful intrusion detection for high-speed networks snore difficult,, and, in certain cases, impossible. The problem of real-time stateful intrusion detection in high-speed networks cannot easily be solved by optimizing the packet; matching algorithm utilized by a, centralized process or by using custom-developed hardware. Instead, there is a need for a parallel approach that is able to decompose the problem into subproblems of manageable size. We present a novel parallel matching algorithm for the signature-based detection of network attacks. The algorithm is able to perform stateful signature matching and has been implemented only using off-the-shelf components. Our initial experiments confirm that, by making the rule snatching process parallel, it is possible to achieve a, scalable implementation of a stateful, network-based intrusion detection system.
引用
收藏
页码:203 / 220
页数:18
相关论文
共 50 条
  • [41] High-Speed Memory-Efficient Network Intrusion Detection System
    Lin, Wei
    Wang, XiaoFei
    Qi, YaXuan
    Pao, Derek
    Liu, Bin
    [J]. IEEE INFOCOM 2009 - IEEE CONFERENCE ON COMPUTER COMMUNICATIONS WORKSHOPS, 2009, : 359 - +
  • [42] Network intrusion detection systems in high-speed traffic in computer networks
    Bul'ajoul, Waleed
    James, Anne
    Pannu, Mandeep
    [J]. 2013 IEEE 10TH INTERNATIONAL CONFERENCE ON E-BUSINESS ENGINEERING (ICEBE), 2013, : 168 - 175
  • [43] High-Speed Railway Clearance Intrusion Detection with Improved SSD Network
    Guo, Baoqing
    Shi, Jiafeng
    Zhu, Liqiang
    Yu, Zujun
    [J]. APPLIED SCIENCES-BASEL, 2019, 9 (15):
  • [44] Approximate reduction of finite automata for high-speed network intrusion detection
    Ceska, Milan
    Havlena, Vojtech
    Holik, Lukas
    Lengal, Ondrej
    Vojnar, Tomas
    [J]. INTERNATIONAL JOURNAL ON SOFTWARE TOOLS FOR TECHNOLOGY TRANSFER, 2020, 22 (05) : 523 - 539
  • [45] One Data Preprocessing Method in High-speed Network Intrusion Detection
    Li, Kunlun
    Zhang, Zhenxing
    Liu, Ming
    [J]. ICWMMN 2010, PROCEEDINGS, 2010, : 60 - 63
  • [46] Intrusion Detection in High-Speed Big Data Networks: A Comprehensive Approach
    Siddique, Kamran
    Akhtar, Zahid
    Kim, Yangwoo
    [J]. ADVANCES IN COMPUTER SCIENCE AND UBIQUITOUS COMPUTING, 2018, 474 : 1364 - 1370
  • [47] Field testing of intrusion detection technologies for high-speed rail crossings
    Blacketer, R
    Zaworski, JR
    Hunter-Zaworski, KM
    [J]. TRAFFIC CONTROL DEVICES, VISIBILITY, AND RAIL-HIGHWAY GRADE CROSSINGS 2005, 2005, (1918): : 10 - 17
  • [48] Study on high-speed network intrusion detection based on network processor
    Computer Network Key Lab., South China University of Technology, Guangzhou 510640, China
    不详
    [J]. Zhongshan Daxue Xuebao, 2006, SUPPL. (31-34):
  • [49] Approximate Reduction of Finite Automata for High-Speed Network Intrusion Detection
    Ceska, Milan
    Havlena, Vojtech
    Holik, Lukas
    Lengal, Ondrej
    Vojnar, Tomas
    [J]. TOOLS AND ALGORITHMS FOR THE CONSTRUCTION AND ANALYSIS OF SYSTEMS, TACAS 2018, PT II, 2018, 10806 : 155 - 175
  • [50] Approximate reduction of finite automata for high-speed network intrusion detection
    Milan Češka
    Vojtěch Havlena
    Lukáš Holík
    Ondřej Lengál
    Tomáš Vojnar
    [J]. International Journal on Software Tools for Technology Transfer, 2020, 22 : 523 - 539