首页> 外文会议>IEEE Military Communications Conference >DISTRIBUTED DATA PARALLEL TECHNIQUES FOR CONTENT-MATCHING INTRUSION DETECTION SYSTEMS
【24h】

DISTRIBUTED DATA PARALLEL TECHNIQUES FOR CONTENT-MATCHING INTRUSION DETECTION SYSTEMS

机译:用于内容匹配的入侵检测系统的分布式数据并行技术

获取原文

摘要

Content matching is a necessary component of any signature-based network Intrusion Detection System (IDS). These packet inspections typically require considerable delay often consuming more than 70% of the IDS processing time. Unfortunately, this delay becomes more significant as security policies and network speeds continue to increase. This paper introduces a new parallel IDS content matching technique that provides initial packet inspections with less delay. The technique distributes portions of a packet payload across an array of n processors, each responsible for scanning a smaller amount of original payload. Given this design, each processor has less data to inspect thus reducing the overall delay. Unlike similar parallel approaches, our technique ensures that security is maintained (no false negatives). Furthermore, the proposed parallel technique is shown to result in an initial match speed-up of approximately 1.25n using Snort (an open source IDS), actual IDS policies, and traffic traces - a significant improvement over current parallel techniques.
机译:内容匹配是基于签名的网络入侵检测系统(ID)的必要组件。这些数据包检查通常需要相当大的延迟,通常造成超过70%的ID处理时间。不幸的是,随着安全策略和网络速度继续增加,这种延迟变得更加重要。本文介绍了一种新的并行IDS内容匹配技术,可提供较少延迟的初始数据包检查。该技术将分组有效载荷的部分分发跨越N个处理器数组,每个都负责扫描较少量的原始有效载荷。鉴于这种设计,每个处理器都有更少的数据来检查,从而降低整体延迟。与类似的并行方法不同,我们的技术确保维护安全性(没有假否定)。此外,所提出的并行技术示出了使用Snort(开源ID),实际ID策略和流量迹线的初始匹配大约1.25n- - 对当前并行技术的显着改进。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号