首页> 外文会议>IEEE Conference on Computer Communications Workshops >STEAL: Service Time-Aware Load balancer on many-core processors for fast intrusion detection
【24h】

STEAL: Service Time-Aware Load balancer on many-core processors for fast intrusion detection

机译:窃取:许多核心处理器上的服务时间感知负载平衡器,用于快速入侵检测

获取原文

摘要

To realize the high-speed intrusion detection by accommodating many regex-based signatures and the growing network link capacities, we propose a Service TimE-Aware Load balancing algorithm, which is called STEAL. This work is motivated from the observation that utilization of the many-core Network Intrusion Detection System (NIDS) is influenced by unfair computational distribution among many-core NIDS nodes. To avoid unfair computational distribution among many-core NIDS nodes, STEAL is designed to dynamically distribute the large volume of traffic among many-core NIDS nodes based on the packet service time, which is represented by the deep packet time in many-core NIDS nodes. From experiments, we show that compared to the commonly used load balancing algorithm based on arrival rate, STEAL increases the number of received packets, i.e., decreases the number of dropped packets, in many-core NIDS. Specifically, by integrating an open source NIDS, i.e. Bro, with STEAL, we show that even under the attack-dominant traffic and many signatures, STEAL can rapidly improve the performance of many-core NIDS to realize the high-speed intrusion detection.
机译:为了实现高速入侵检测,通过适应基于正则表达式的签名和不断增长的网络链路容量,提出了一种服务时感知负载平衡算法,称为窃取。这项工作是激励的观察,即利用许多核心网络入侵检测系统(NIDS)的利用受到许多核心NIDS节点之间的不公平计算分布的影响。为避免在许多核心NIDS节点之间的不公平计算分布,窃取旨在根据数据包服务时间动态分布许多核心NIDS节点之间的大量流量,这些数据包服务时间由许多核心NIDS节点中的深度数据包时间表示。从实验表明,与基于到达速率的常用负载平衡算法相比,窃取增加了所接收的数据包的数量,即,降低许多核心NID中的丢弃数据包的数量。具体而言,通过集成开源nids,即兄弟,随着窃取,我们表明即使在攻击主导的流量和许多签名下,窃取也可以迅速提高许多核心NID的性能,以实现高速入侵检测。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号