Analysing performance issues of open-source intrusion detection systems in high-speed networks

被引:13
|
作者
Hu, Qinwen [1 ]
Yu, Se-Young [2 ]
Asghar, Muhammad Rizwan [1 ]
机构
[1] Univ Auckland, Sch Comp Sci, Auckland, New Zealand
[2] Northwestern Univ, Int Ctr Adv Internet Res, Evanston, IL 60208 USA
关键词
D O I
10.1016/j.jisa.2019.102426
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Driven by the growing data transfer needs, industry and research institutions are deploying 100 Gb/s networks. As such high-speed networks become prevalent, these also introduce significant technical challenges. In particular, an Intrusion Detection System (IDS) cannot process network activities at such a high rate when monitoring large and diverse traffic volumes, thus resulting in packet drops. Unfortunately, the high packet drop rate has a significant impact on detection accuracy. In this work, we investigate two popular open-source IDSs: Snort and Suricata along with their comparative performance benchmarks to better understand drop rates and detection accuracy in 100 Gb/s networks. More specifically, we study vital factors (including system resource usage, packet processing speed, packet drop rate, and detection accuracy) that limit the applicability of IDSs to high-speed networks. Furthermore, we provide a comprehensive analysis to show the performance impact on IDSs by using different configurations, traffic volumes and different flows. Finally, we identify challenges of using open-source IDSs in high-speed networks and provide suggestions to help network administrators to address identified issues and give some recommendations for developing new IDSs that can be used for high-speed networks. (C) 2020 Elsevier Ltd. All rights reserved.
引用
收藏
页数:10
相关论文
共 50 条
  • [21] Adaptive rate control in high-speed networks: performance issues
    Abdelaziz, M
    Stavrakakis, I
    COMPUTER NETWORKS-THE INTERNATIONAL JOURNAL OF COMPUTER AND TELECOMMUNICATIONS NETWORKING, 2001, 37 (3-4): : 363 - 382
  • [22] RemoteEye: An open-source high-speed remote eye trackerImplementation insights of a pupil- and glint-detection algorithm for high-speed remote eye tracking
    Benedikt Hosp
    Shahram Eivazi
    Maximilian Maurer
    Wolfgang Fuhl
    David Geisler
    Enkelejda Kasneci
    Behavior Research Methods, 2020, 52 : 1387 - 1401
  • [23] CompoundRay, an open-source tool for high-speed and high-fidelity rendering of compound eyes
    Millward, Blayze
    Maddock, Steve
    Mangan, Michael
    ELIFE, 2022, 11
  • [24] Current issues in high-speed networks
    Saleh, KA
    Tariq, S
    Dhodhi, MK
    COMPUTER COMMUNICATIONS, 2001, 24 (17) : 1687 - 1688
  • [25] Commercial and open-source based Intrusion Detection System and Intrusion Prevention System (IDS/IPS) design for an IP networks
    Hock, Filip
    Kortis, Peter
    2015 13TH INTERNATIONAL CONFERENCE ON EMERGING ELEARNING TECHNOLOGIES AND APPLICATIONS (ICETA), 2015, : 99 - 102
  • [26] Diversity in Open Source Intrusion Detection Systems
    Asad, Hafizul
    Gashi, Ilir
    COMPUTER SAFETY, RELIABILITY, AND SECURITY (SAFECOMP 2018), 2018, 11093 : 267 - 281
  • [27] Intrusion detection system for high-speed network
    Yang, W
    Fang, BX
    Liu, B
    Zhang, HL
    COMPUTER COMMUNICATIONS, 2004, 27 (13) : 1288 - 1294
  • [28] High-speed device synchronization in optical microscopy with an open-source hardware control platform
    Colville, Marshall J.
    Park, Sangwoo
    Zipfel, Warren R.
    Paszek, Matthew J.
    SCIENTIFIC REPORTS, 2019, 9 (1)
  • [29] Hadoop Based Real-time Intrusion Detection for High-speed Networks
    Rathore, M. Mazhar
    Paul, Anand
    Ahmad, Awais
    Rho, Seungmin
    Imran, Muhammad
    Guizani, Mohsen
    2016 IEEE GLOBAL COMMUNICATIONS CONFERENCE (GLOBECOM), 2016,
  • [30] Pi-IDS: Evaluation of Open-Source Intrusion Detection Systems on Raspberry Pi 2
    Kyaw, Ar Kar
    Chen, Yuzhu
    Joseph, Justin
    2015 SECOND INTERNATIONAL CONFERENCE ON INFORMATION SECURITY AND CYBER FORENSICS (INFOSEC), 2015, : 165 - 170