首页> 外文会议>Applied Cryptography and Network Security >A Parallel Intrusion Detection System for High-Speed Networks
【24h】

A Parallel Intrusion Detection System for High-Speed Networks

机译:高速网络并行入侵检测系统

获取原文

摘要

The process speed of network-based intrusion detection systems (NIDSs) is still low compared with the speed of networks. As a result, few NIDS is applicable in a high-speed network. A parallel NIDS for high-speed networks is presented in this paper. By dividing the overall traffic into small slices, several sensors can analyze the traffic concurrently and significantly increase the process speed. For most attacks, our partition algorithm ensures that a single slice contains all the evidence necessary to detect a specific attack, making sensor-to-sensor interaction unnecessary. Meanwhile, by making use of the character of the network traffic, the algorithm can also dynamically balance all sensors' loads. To keep the system as simple as possible, a specific sensor is used to detect the scan and the DoS attack. Although only one sensor is used for this kind of attacks, we argue that our system can still provide high process ability.
机译:与网络速度相比,基于网络的入侵检测系统(NIDS)的处理速度仍然很低。结果,几乎没有NIDS适用于高速网络。本文介绍了一种用于高速网络的并行NIDS。通过将总流量分成小片,多个传感器可以同时分析流量,并显着提高处理速度。对于大多数攻击,我们的分区算法可确保单个切片包含检测特定攻击所需的所有证据,从而无需进行传感器之间的交互。同时,利用网络流量的特性,该算法还可以动态平衡所有传感器的负载。为了使系统尽可能简单,使用特定的传感器来检测扫描和DoS攻击。尽管只有一个传感器用于这种攻击,但我们认为我们的系统仍可以提供较高的处理能力。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号