首页> 外文会议>6th ACM conference on emerging networking experiments and technologies 2010 >Network-Wide Deployment of Intrusion Detection and Prevention Systems
【24h】

Network-Wide Deployment of Intrusion Detection and Prevention Systems

机译:入侵检测和防御系统的网络范围部署

获取原文
获取原文并翻译 | 示例

摘要

Traditional efforts for scaling network intrusion detection (NIDS) and intrusion prevention systems (NIPS) have largely focused on a single-vantage-point view. In this paper, we explore an alternative design that exploits spatial, network-wide opportunities for distributing NIDS and NIPS functions. For the NIDS case, we design a linear programming formulation to assign detection responsibilities to nodes while ensuring that no node is overloaded. We describe a prototype NIDS implementation adapted from the Bro system to analyze traffic per these assignments, and demonstrate the advantages that this approach achieves. For NIPS, we show how to maximally leverage specialized hardware (e.g., TCAMs) to reduce the footprint of unwanted traffic on the network. Such hardware constraints make the optimization problem NP-hard, and we provide practical approximation algorithms based on randomized rounding.
机译:扩展网络入侵检测(NIDS)和入侵防御系统(NIPS)的传统工作主要集中在单优势点视图上。在本文中,我们探索了一种替代设计,该设计利用空间,网络范围内的机会来分配NIDS和NIPS功能。对于NIDS,我们设计了线性规划公式,以将检测职责分配给节点,同时确保没有节点过载。我们描述了从Bro系统改编而成的NIDS原型实现,以分析这些分配的流量,并演示了这种方法的优势。对于NIPS,我们展示了如何最大程度地利用专用硬件(例如TCAM)来减少网络上不必要的流量所占用的空间。这样的硬件限制使优化问题难以解决,我们提供了基于随机舍入的实用近似算法。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号