Real-time intrusion detection for high-speed networks

被引:22
|
作者
Jiang, WB [1 ]
Song, H [1 ]
Dai, YQ [1 ]
机构
[1] Tsing Hua Univ, Dept Comp Sci & Technol, Beijing 100084, Peoples R China
基金
中国国家自然科学基金;
关键词
network security; intrusion detection; high-speed network; load balancing; multi-pattern string matching algorithm;
D O I
10.1016/j.cose.2004.07.005
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Network-based intrusion detection systems (NIDSs) frequently have problems with handling heavy traffic toads in real-time, which result in packet loss and false negatives. This paper presents a high-performance network intrusion detection system, called HPMonitor, which combines a high-efficiency detection engine and a load-balancing device to address these problems. The paper describes HPMonitor's system architecture, discusses a flow-based dynamic load-balancing algorithm called dynamic least toad first (DLLF) algorithm, and introduces a new multi-pattern string matching algorithm called shift max algorithm (SMA). The test results reveal that the DLLF algorithm is, an effective balancing algorithm for NIDS. Meanwhile, the experimental results show that the SMA algorithm is faster in searching large sets of patterns when compared with other algorithms, and its performance is affected little when the patterns set number increases. (C)2004 Elsevier Ltd. All rights reserved.
引用
收藏
页码:287 / 294
页数:8
相关论文
共 50 条
  • [1] Hadoop Based Real-time Intrusion Detection for High-speed Networks
    Rathore, M. Mazhar
    Paul, Anand
    Ahmad, Awais
    Rho, Seungmin
    Imran, Muhammad
    Guizani, Mohsen
    [J]. 2016 IEEE GLOBAL COMMUNICATIONS CONFERENCE (GLOBECOM), 2016,
  • [2] BigFlow: Real-time and reliable anomaly-based intrusion detection for high-speed networks
    Viegas, Eduardo
    Santin, Altair
    Bessani, Alysson
    Neves, Nuno
    [J]. FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2019, 93 : 473 - 485
  • [3] REAL-TIME TRAFFIC MEASUREMENTS FOR HIGH-SPEED NETWORKS
    HERSHEY, PC
    SILIO, CB
    WACLAWSKY, JG
    [J]. BT TECHNOLOGY JOURNAL, 1995, 13 (03): : 113 - 122
  • [4] Real-time Intrusion Detection Algorithm for High-speed Railway Based on Feature Map Pruning
    Wang, Wei
    Zhu, Liqiang
    [J]. Tiedao Xuebao/Journal of the China Railway Society, 2019, 41 (09): : 74 - 80
  • [5] A stateful real time intrusion detection system for high-speed network
    Sourour, Meharouech
    Adel, Bouhoula
    Tarek, Abbes
    [J]. 21st International Conference on Advanced Networking and Applications, Proceedings, 2007, : 404 - 411
  • [6] Efficient Intrusion Detection for High-speed Networks
    Ma, Gaolong
    Tang, Wen
    [J]. INFORMATION TECHNOLOGY APPLICATIONS IN INDUSTRY, PTS 1-4, 2013, 263-266 : 2915 - 2919
  • [7] Intrusion detection and simulation for high-speed networks
    Yu, F
    Dai, XP
    Shen, Y
    Huang, H
    Zhu, ML
    [J]. 2005 INTERNATIONAL CONFERENCE ON SERVICES SYSTEMS AND SERVICES MANAGEMENT, VOLS 1 AND 2, PROCEEDINGS, 2005, : 835 - 840
  • [8] Stateful intrusion detection for high-speed networks
    Kruegel, C
    Valeur, F
    Vigna, G
    Kemmerer, R
    [J]. 2002 IEEE SYMPOSIUM ON SECURITY AND PRIVACY, PROCEEDINGS, 2002, : 285 - 293
  • [9] CAMNEP: An intrusion detection system for high-speed networks
    Rehák, Martin
    Pechouček, Michal
    Bartoš, Karel
    Grill, Martin
    Čeleda, Pavel
    Krmíček, Vojtech
    [J]. Progress in Informatics, 2008, (05): : 65 - 74
  • [10] High-speed real-time simulation
    Crosbie, Roy E.
    [J]. AMS 2007: FIRST ASIA INTERNATIONAL CONFERENCE ON MODELLING & SIMULATION ASIA MODELLING SYMPOSIUM, PROCEEDINGS, 2007, : 7 - 12