首页> 外文会议>International Conference on Information and Communication Technologies >Performance Enhancement of Snort IDS through Kernel Modification
【24h】

Performance Enhancement of Snort IDS through Kernel Modification

机译:通过内核修改进行Snort ID的性能增强

获取原文

摘要

Performance and improved packet handling capacity against high traffic load are important requirements for an effective intrusion detection system (IDS). Snort is one of the most popular open-source intrusion detection system which runs on Linux. This research article discusses ways of enhancing the performance of Snort by modifying Linux key parameters related to NAPI packet reception mechanism within the Linux kernel networking subsystem. Our enhancement overcomes the current limitations related to NAPI throughput. We experimentally demonstrate that current default budget B value of 300 does not yield the best performance of Snort throughput. We show that a small budget value of 14 gives the best Snort performance in terms of packet loss both at Kernel subsystem and at the application level. Furthermore, we compare our results to those reported in the literature, and we show that our enhancement through tuning certain parameters yield superior performance.
机译:对高流量负荷的性能和改进的数据包处理能力是有效入侵检测系统(IDS)的重要要求。 Snort是在Linux上运行的最受欢迎的开源入侵检测系统之一。本研究文章讨论了通过修改与Linux内核网络子系统内的NAPI分组接收机制相关的Linux密钥参数来提高Snort的性能的方法。我们的增强克服了与NAPI吞吐量相关的当前限制。我们通过实验证明,当前默认预算B值为300不会产生Snort吞吐量的最佳性能。我们表明,小型预算值14在内核子系统和应用程序级别的数据包丢失方面给出了最佳的Snort性能。此外,我们将结果与文献中报告的结果进行比较,我们展示了我们通过调整某些参数的增强,从而产生卓越的性能。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号