【24h】

Operational Experiences with High-Volume Network Intrusion Detection

机译:大容量网络入侵检测的运营经验

获取原文
获取原文并翻译 | 示例

摘要

In large-scale environments, network intrusion detection systems (NIDSs) face extreme challenges with respect to traffic volume, traffic diversity, and resource management. While crucial for acceptance and operational deployment, the research literature mainly omits such practical difficulties. In this paper, we offer an evaluation based on extensive operational experience. More specifically, we identify and explore key factors with respect to resource management and efficient packet processing and highlight their impact using a set of real-world traces. On the one hand, these insights help us gauge the trade-offs of tuning a NIDS. On the other hand, they motivate us to explore several novel ways of reducing resource requirements. These enable us to improve the state management considerably as well as balance the processing load dynamically. Overall this enables us to operate a NIDS successfully in our high-volume network environments.
机译:在大规模环境中,网络入侵检测系统(NIDS)在流量,流量多样性和资源管理方面面临着严峻的挑战。尽管对于接受和部署业务至关重要,但研究文献主要忽略了此类实际困难。在本文中,我们将基于丰富的运营经验进行评估。更具体地说,我们确定并探索与资源管理和有效数据包处理有关的关键因素,并使用一组真实世界的踪迹突出显示它们的影响。一方面,这些见解有助于我们评估调整NIDS的权衡。另一方面,它们激励我们探索减少资源需求的几种新颖方法。这些使我们能够大大改善状态管理并动态地平衡处理负载。总体而言,这使我们能够在我们的大容量网络环境中成功运行NIDS。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号