...
首页> 外文期刊>Journal of network and computer applications >Performance evaluation comparison of Snort NIDS under Linux and Windows Server
【24h】

Performance evaluation comparison of Snort NIDS under Linux and Windows Server

机译:Linux和Windows Server下Snort NIDS的性能评估比较

获取原文
获取原文并翻译 | 示例
   

获取外文期刊封面封底 >>

       

摘要

In this paper, we present an experimental evaluation and comparison of the performance of Snort NIDS when running under the two popular platforms of Linux and Windows 2003 Server. Snort's performance is measured when subjecting a PC host running Snort to both normal and malicious traffic, and with different traffic load conditions. Snort's performance is evaluated and compared in terms of throughput and packet loss. In order to offer sound interpretations and get better insight into the behavior of Snort, we also measure the packet loss encountered at the kernel level. In addition, we identify key system parameters (for both Linux and Windows) that provide a fine-grained control over the percentage of the CPU bandwidth allocated to Snort application and can consequently impact its performance. We investigate such an impact, and determine the most appropriate values to improve and optimize Snort's performance. Specifically, for Windows we investigate the impact of customizing the Processor Scheduling configuration option; and for Linux, we investigate the impact of tuning the Budget configurable parameter used in the Linux kernel's packet reception mechanism.
机译:在本文中,我们将对在两种流行的Linux和Windows 2003 Server平台上运行Snort NIDS时的性能进行实验评估和比较。当使运行Snort的PC主机同时受到正常流量和恶意流量以及不同流量负载条件的影响时,Snort的性能即得到衡量。 Snort的性能将根据吞吐量和丢包情况进行评估和比较。为了提供合理的解释并更好地了解Snort的行为,我们还测量了内核级别遇到的数据包丢失。此外,我们确定了关键的系统参数(适用于Linux和Windows),这些参数可对分配给Snort应用程序的CPU带宽百分比进行精细控制,从而影响其性能。我们调查这种影响,并确定最合适的值来改善和优化Snort的性能。具体来说,对于Windows,我们研究了定制“处理器调度”配置选项的影响。对于Linux,我们研究了调整Linux内核的数据包接收机制中使用的Budget可配置参数的影响。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号