Real-time intrusion detection for high-speed networks

被引:23
作者
Jiang, WB [1 ]
Song, H [1 ]
Dai, YQ [1 ]
机构
[1] Tsing Hua Univ, Dept Comp Sci & Technol, Beijing 100084, Peoples R China
基金
中国国家自然科学基金;
关键词
network security; intrusion detection; high-speed network; load balancing; multi-pattern string matching algorithm;
D O I
10.1016/j.cose.2004.07.005
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Network-based intrusion detection systems (NIDSs) frequently have problems with handling heavy traffic toads in real-time, which result in packet loss and false negatives. This paper presents a high-performance network intrusion detection system, called HPMonitor, which combines a high-efficiency detection engine and a load-balancing device to address these problems. The paper describes HPMonitor's system architecture, discusses a flow-based dynamic load-balancing algorithm called dynamic least toad first (DLLF) algorithm, and introduces a new multi-pattern string matching algorithm called shift max algorithm (SMA). The test results reveal that the DLLF algorithm is, an effective balancing algorithm for NIDS. Meanwhile, the experimental results show that the SMA algorithm is faster in searching large sets of patterns when compared with other algorithms, and its performance is affected little when the patterns set number increases. (C)2004 Elsevier Ltd. All rights reserved.
引用
收藏
页码:287 / 294
页数:8
相关论文
共 9 条
[1]   EFFICIENT STRING MATCHING - AID TO BIBLIOGRAPHIC SEARCH [J].
AHO, AV ;
CORASICK, MJ .
COMMUNICATIONS OF THE ACM, 1975, 18 (06) :333-340
[2]  
ALLEN J, 2000, CMUSEI99TR028 CARN M
[3]   FAST STRING SEARCHING ALGORITHM [J].
BOYER, RS ;
MOORE, JS .
COMMUNICATIONS OF THE ACM, 1977, 20 (10) :762-772
[4]  
COMMENTZWALTER B, 1979, LECTURE NOTES COMPUT, V71, P118
[5]  
KRUEGEL C, 2001, STATEFUL INTRUSION D
[6]  
*NSS GROUP, 2000, INTR DET VULN ASS
[7]  
*TOPL NETW, 2004, IDS BAL
[8]   ONLINE CONSTRUCTION OF SUFFIX TREES [J].
UKKONEN, E .
ALGORITHMICA, 1995, 14 (03) :249-260
[9]  
WATSON BW, 1994, COMPUT SCI NOTES, V9419