...
首页> 外文期刊>International journal of computer science and network security >Performance Improvement by Coordinating Configurations of Independently-managed NIDS
【24h】

Performance Improvement by Coordinating Configurations of Independently-managed NIDS

机译:通过协调独立管理的NIDS的配置来提高性能

获取原文
获取原文并翻译 | 示例
   

获取外文期刊封面封底 >>

       

摘要

Because of today's increased traffic volume and sophisticated attacks, implementing a network intrusion detection/prevention system (NIDS/NIPS) with a single workstation has been challenging. In this paper, we propose Brownie, a system for improving performance by coordinating configurations of already-existing, independently-managed NIDSs in an organization. Instead of installing one expensive hardware or parallel NIDSs at a network entry point, Brownie achieves performance improvement by 1) offloading overloaded NIDS, and 2) eliminating redundant rules. First, Brownie exchanges NIDSs' load status and transfers some rules from overloaded to light-loaded NIDSs, which prevents the overloaded NIDSs from bottlenecking the network. Second, if some NIDSs on a network path enable the same rules, Brownie eliminates the redundant rules, which reduces the aggregate overhead of the NIDSs. The experimental results with a web server benchmark suggest that Brownie increases the benchmark throughput by more than 10%. In addition, Brownie running with a university full-packet trace successfully offloads overloaded NIDS and eliminates redundant rules.
机译:由于当今流量的增加和复杂的攻击,用单个工作站实施网络入侵检测/防御系统(NIDS / NIPS)一直是一个挑战。在本文中,我们提出了布朗尼(Brownie)系统,该系统通过协调组织中已经存在的,独立管理的NIDS的配置来提高性能。而不是在网络入口点安装昂贵的硬件或并行NIDS,而是通过1)卸载过载的NIDS和2)消除冗余规则来提高性能。首先,布朗尼交换NIDS的负载状态,并将一些规则从过载的NIDS转移到轻载的NIDS,这可以防止过载的NIDS阻塞网络。其次,如果网络路径上的某些NIDS启用相同的规则,则Brownie消除了冗余规则,从而减少了NIDS的总开销。 Web服务器基准测试的实验结果表明,Brownie将基准吞吐量提高了10%以上。此外,运行有大学完整数据包跟踪的Brownie成功卸载了过载的NIDS,并消除了冗余规则。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号