首页> 外文会议>18th ACM conference on computer amp; communications security. >MIDeA: A Multi-Parallel Intrusion Detection Architecture
【24h】

MIDeA: A Multi-Parallel Intrusion Detection Architecture

机译:MIDeA:多并行入侵检测架构

获取原文
获取原文并翻译 | 示例

摘要

Network intrusion detection systems are faced with the challenge of identifying diverse attacks, in extremely high speed networks. For this reason, they must operate at multi-Gigabit speeds, while performing highly-complex per-packet and per-flow data processing. In this paper, we present a multi-parallel intrusion detection architecture tailored for high speed networks. To cope with the increased processing throughput requirements, our system parallelizes network traffic processing and analysis at three levels, using multi-queue NICs, multiple CPUs, and multiple GPUs. The proposed design avoids locking, optimizes data transfers between the different processing units, and speeds up data processing by mapping different operations to the processing units where they are best suited. Our experimental evaluation shows that our prototype implementation based on commodity off-the-shelf equipment can reach processing speeds of up to 5.2 Gbit/s with zero packet loss when analyzing traffic in a real network, whereas the pattern matching engine alone reaches speeds of up to 70 Gbit/s, which is an almost four times improvement over prior solutions that use specialized hardware.
机译:在极高速的网络中,网络入侵检测系统面临着识别各种攻击的挑战。因此,它们必须以千兆速率运行,同时执行高度复杂的每个数据包和每个流数据处理。在本文中,我们提出了针对高速网络量身定制的多并行入侵检测架构。为了满足不断增长的处理吞吐量要求,我们的系统使用多队列NIC,多个CPU和多个GPU在三个级别上并行处理网络流量。提出的设计避免了锁定,优化了不同处理单元之间的数据传输,并通过将不同的操作映射到最适合它们的处理单元来加快数据处理。我们的实验评估表明,我们的基于现成设备的原型实现在分析真实网络中的流量时可以达到高达5.2 Gbit / s的处理速度,而零丢包,而仅模式匹配引擎就可以达到最高可达70 Gbit / s,这是使用专用硬件的现有解决方案的近四倍。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号