首页> 外文学位 >On optimizing traffic distribution for clusters of network intrusion detection and prevention systems.
【24h】

On optimizing traffic distribution for clusters of network intrusion detection and prevention systems.

机译:关于优化网络入侵检测和防御系统集群的流量分配。

获取原文
获取原文并翻译 | 示例

摘要

To address the overload conditions caused by the increasing network traffic volume, recent literature in the network intrusion detection and prevention field has proposed the use of clusters of network intrusion detection and prevention systems (NIDPSs). We observe that simple traffic distribution schemes are usually used for NIDPS clusters. These schemes have two major drawbacks: (1) the loss of correlation information caused by the traffic distribution because correlated flows are not sent to the same NIDPS; and (2) the unbalanced loads of the NIDPSs. The first drawback severely affects the ability to detect intrusions that require analysis of correlated flows. The second drawback greatly increases the chance of overloading an NIDPS even when loads of the others are low.;We have implemented prototypes of both systems and evaluated them using extensive simulations and real traffic traces. Overall, the evaluation results show that both systems have low overhead in terms of the delays introduced to the packets. More importantly, compared to the naive hash-based distribution, the Load Balancer significantly improves the anomaly-based detection accuracy of DDoS attacks and port scans - the two major attacks that require the analysis of correlated flows - meanwhile, the Load Manager successfully maintains the anomaly-based detection accuracy of these two major attacks of the NIDPSs.;In this thesis, we address these two drawbacks. In particular, we propose two novel traffic distribution systems: the Correlation-Based Load Balancer and the Correlation-Based Load Manager as two different solutions to the NIDPS traffic distribution problem. On the one hand, the Load Balancer and the Load Manager both consider the current loads of the NIDPSs while distributing traffic to provide fine-grained load balancing and dynamic load distribution, respectively. On the other hand, both systems take into account traffic correlation in their distributions, thereby significantly reducing the loss of correlation information during their distribution of traffic.
机译:为了解决由网络流量增加引起的过载情况,网络入侵检测和防御领域中的最新文献提出了使用网络入侵检测和防御系统(NIDPS)集群的方法。我们观察到简单的流量分配方案通常用于NIDPS群集。这些方案具有两个主要缺点:(1)由于业务量分配引起的相关信息的丢失,因为相关流没有被发送到相同的NIDPS; (2)NIDPS的不平衡负载。第一个缺点严重影响了检测需要分析相关流的入侵的能力。第二个缺点极大地增加了NIDPS过载的机会,即使其他负载很低。我们已经实现了这两个系统的原型,并使用大量的仿真和真实的交通跟踪对其进行了评估。总体而言,评估结果表明,就引入数据包的延迟而言,两个系统的开销都较低。更重要的是,与基于朴素的散列分布相比,Load Balancer显着提高了DDoS攻击和端口扫描(这是需要对相关流进行分析的两种主要攻击)基于异常的检测准确性-同时,Load Manager成功地维护了NIDPS的这两种主要攻击的基于异常的检测精度。;本文解决了这两个缺陷。特别是,我们提出了两种新颖的流量分配系统:基于相关的负载均衡器和基于相关的负载管理器,作为解决NIDPS流量分配问题的两种不同解决方案。一方面,负载均衡器和负载管理器在分配流量时都考虑了NIDPS的当前负载,分别提供细粒度的负载均衡和动态负载分配。另一方面,两个系统在其分配中都考虑了流量相关性,从而显着减少了流量分配期间相关性信息的丢失。

著录项

  • 作者

    Le, Anh.;

  • 作者单位

    University of Waterloo (Canada).;

  • 授予单位 University of Waterloo (Canada).;
  • 学科 Mathematics.;Computer science.
  • 学位 M.Math.
  • 年度 2008
  • 页码 96 p.
  • 总页数 96
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号