Analysing performance issues of open-source intrusion detection systems in high-speed networks

被引:13
|
作者
Hu, Qinwen [1 ]
Yu, Se-Young [2 ]
Asghar, Muhammad Rizwan [1 ]
机构
[1] Univ Auckland, Sch Comp Sci, Auckland, New Zealand
[2] Northwestern Univ, Int Ctr Adv Internet Res, Evanston, IL 60208 USA
关键词
D O I
10.1016/j.jisa.2019.102426
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Driven by the growing data transfer needs, industry and research institutions are deploying 100 Gb/s networks. As such high-speed networks become prevalent, these also introduce significant technical challenges. In particular, an Intrusion Detection System (IDS) cannot process network activities at such a high rate when monitoring large and diverse traffic volumes, thus resulting in packet drops. Unfortunately, the high packet drop rate has a significant impact on detection accuracy. In this work, we investigate two popular open-source IDSs: Snort and Suricata along with their comparative performance benchmarks to better understand drop rates and detection accuracy in 100 Gb/s networks. More specifically, we study vital factors (including system resource usage, packet processing speed, packet drop rate, and detection accuracy) that limit the applicability of IDSs to high-speed networks. Furthermore, we provide a comprehensive analysis to show the performance impact on IDSs by using different configurations, traffic volumes and different flows. Finally, we identify challenges of using open-source IDSs in high-speed networks and provide suggestions to help network administrators to address identified issues and give some recommendations for developing new IDSs that can be used for high-speed networks. (C) 2020 Elsevier Ltd. All rights reserved.
引用
收藏
页数:10
相关论文
共 50 条
  • [31] High-speed device synchronization in optical microscopy with an open-source hardware control platform
    Marshall J. Colville
    Sangwoo Park
    Warren R. Zipfel
    Matthew J. Paszek
    Scientific Reports, 9
  • [32] Intrusion detection alert management for high-speed networks: current researches and applications
    Sallay, Hassen
    Bourouis, Sami
    SECURITY AND COMMUNICATION NETWORKS, 2015, 8 (18) : 4362 - 4372
  • [33] RemoteEye: An open-source high-speed remote eye tracker Implementation insights of a pupil- and glint-detection algorithm for high-speed remote eye tracking
    Hosp, Benedikt
    Eivazi, Shahram
    Maurer, Maximilian
    Fuhl, Wolfgang
    Geisler, David
    Kasneci, Enkelejda
    BEHAVIOR RESEARCH METHODS, 2020, 52 (03) : 1387 - 1401
  • [34] HIGH-SPEED NETWORKS AND THEIR PERFORMANCE
    VINIOTIS, I
    PERROS, H
    PERFORMANCE EVALUATION, 1995, 22 (03) : 193 - 194
  • [35] Open-Source RTP Library for High-Speed 4K HEVC Video Streaming
    Altonen, Aaro
    Rasanen, Joni
    Laitinen, Jaakko
    Viitanen, Marko
    Vanne, Jarno
    2020 IEEE 22ND INTERNATIONAL WORKSHOP ON MULTIMEDIA SIGNAL PROCESSING (MMSP), 2020,
  • [36] Security issues in information systems based on open-source technologies
    Greiner, S
    Boskovic, B
    Brest, J
    Zumer, V
    IEEE REGION 8 EUROCON 2003, VOL B, PROCEEDINGS: COMPUTER AS A TOOL, 2003, : 12 - 15
  • [37] EyeLoop: An Open-Source System for High-Speed, Closed-Loop Eye-Tracking
    Arvin, Simon
    Rasmussen, Rune Nguyen
    Yonehara, Keisuke
    FRONTIERS IN CELLULAR NEUROSCIENCE, 2021, 15
  • [38] A perspective–retrospective analysis of diversity in signature-based open-source network intrusion detection systems
    H. Asad
    S. Adhikari
    Ilir Gashi
    International Journal of Information Security, 2024, 23 : 1331 - 1346
  • [39] Analyzing open-source software systems as complex networks
    Zheng, Xiaolong
    Zeng, Daniel
    Li, Huiqian
    Wang, Feiyue
    PHYSICA A-STATISTICAL MECHANICS AND ITS APPLICATIONS, 2008, 387 (24) : 6190 - 6200
  • [40] Developing an Intrusion Detection Framework for High-Speed Big Data Networks: A Comprehensive Approach
    Siddique, Kamran
    Akhtar, Zahid
    Khan, Muhammad Ashfaq
    Jung, Yong-Hwan
    Kim, Yangwoo
    KSII TRANSACTIONS ON INTERNET AND INFORMATION SYSTEMS, 2018, 12 (08): : 4021 - 4037