Performance improvement by means of collaboration between network intrusion detection systems

Miyuki Hanaoka, Kenji Kono, Toshio Hirotsu

研究成果: Conference contribution

抄録

Because of today's increased traffic volume and sophisticated attacks, implementing a network intrusion detection/ prevention system (NIDS/NIPS) with a single workstation has been challenging. In this paper, we propose Brownie, a system for improving performance by means of collaboration between already-existing NIDSs, instead of installing one expensive hardware or parallel NIDS at a network entry point. Our Brownie achieves performance improvement by 1) offloading overloaded NIDS, and 2) eliminating redundant rules. First, a Brownie exchanges NIDSs' load status and transfers some rules from overloaded to light-loaded NIDSs, which prevents the overloaded NIDSs from bottlenecking the network. Second, if some NIDSs in a network path enable the same rules, a Brownie eliminates the redundant rules, which reduces the aggregate overhead of the NIDSs. The experimental results with a university full-packet trace suggest that Brownies successfully offloads overloaded NIDS and eliminates redundant rules.

本文言語English
ホスト出版物のタイトルProceedings of the 7th Annual Communication Networks and Services Research Conference, CNSR 2009
ページ262-269
ページ数8
DOI
出版ステータスPublished - 2009
外部発表はい
イベント7th Annual Communication Networks and Services Research Conference, CNSR 2009 - Moncton, NB, Canada
継続期間: 2009 5 112009 5 13

出版物シリーズ

名前Proceedings of the 7th Annual Communication Networks and Services Research Conference, CNSR 2009

Other

Other7th Annual Communication Networks and Services Research Conference, CNSR 2009
国/地域Canada
CityMoncton, NB
Period09/5/1109/5/13

ASJC Scopus subject areas

  • コンピュータ ネットワークおよび通信
  • 電子工学および電気工学

フィンガープリント

「Performance improvement by means of collaboration between network intrusion detection systems」の研究トピックを掘り下げます。これらがまとまってユニークなフィンガープリントを構成します。

引用スタイル