首页> 外文期刊>Emerging Topics in Computing, IEEE Transactions on >LEoNIDS: A Low-Latency and Energy-Efficient Network-Level Intrusion Detection System
【24h】

LEoNIDS: A Low-Latency and Energy-Efficient Network-Level Intrusion Detection System

机译:LEoNIDS:一种低延迟且节能的网络级入侵检测系统

获取原文
获取原文并翻译 | 示例

摘要

Over the past decade, design and implementation of low-power systems has received significant attention. While it started with data centers and battery-operated mobile devices, it has recently branched to core network devices such as routers. However, this emerging need for low-power system design has not been studied for security systems, which are becoming increasingly important today. Toward this direction, we aim to reduce the power consumption of network-level intrusion detection systems (NIDS), which are used to improve the secure operation of modern computer networks. Unfortunately, traditional approaches to low-power system design, such as frequency scaling, lead to a disproportionate increase in packet processing and queuing times. In this paper, we show that this increase has a negative impact on the detection latency and impedes a timely reaction. To address this issue, we present a low-latency and energy-efficient NIDS (LEoNIDS): an architecture that resolves the energy-latency tradeoff by providing both low power consumption and low detection latency at the same time. The key idea is to identify the packets that are more likely to carry an attack and give them higher priority so as to achieve low attack detection latency. Our results indicate that LEoNIDS consumes power comparable to a state-of-the-art low-power design, while, at the same time, achieving up to an order of magnitude faster attack detection.
机译:在过去的十年中,低功耗系统的设计和实现受到了广泛的关注。当它始于数据中心和电池供电的移动设备时,它最近已扩展到诸如路由器之类的核心网络设备。但是,对于低功耗系统设计的这种新兴需求尚未针对安全系统进行研究,安全系统在今天变得越来越重要。朝这个方向发展,我们旨在降低网络级入侵检测系统(NIDS)的功耗,该系统用于改善现代计算机网络的安全运行。不幸的是,诸如频率缩放之类的用于低功率系统设计的传统方法导致分组处理和排队时间的不成比例的增加。在本文中,我们表明此增加对检测延迟有负面影响并阻碍及时反应。为了解决这个问题,我们提出了一种低延迟和高能效的NIDS(LEoNIDS):一种通过同时提供低功耗和低检测延迟来解决能量延迟权衡的架构。关键思想是识别出更有可能遭受攻击的数据包并为其赋予更高的优先级,从而实现较低的攻击检测延迟。我们的结果表明,LEoNIDS的功耗可与最新的低功耗设计相媲美,同时,可以将攻击检测速度提高多达一个数量级。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号