Intrusion detection system for high-speed network

被引:15
作者
Yang, W [1 ]
Fang, BX
Liu, B
Zhang, HL
机构
[1] Harbin Inst Technol, Comp Network & Informat Secur Technol Res Ctr, Harbin 150001, Peoples R China
[2] Univ Houston, Dept Comp Sci, Houston, TX 77204 USA
关键词
intrusion detection; high-speed network; packet capture; protocol analysis; multi-pattern matching;
D O I
10.1016/j.comcom.2004.03.001
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The increasing network throughput challenges the current Network Intrusion Detection Systems (NIDS) to have compatible high-performance data processing. In this paper, we describe an in-depth research on the related techniques of high-performance network intrusion detection and an implementation of a Rule-based High-performance Network Intrusion Detection System (RHPNIDS) for high-speed networks. By integrating several performance optimizing methods, the performance of RHPNIDS is very impressive compared with the popular open source NIDS Snort. (C) 2004 Elsevier B.V. All rights reserved.
引用
收藏
页码:1288 / 1294
页数:7
相关论文
共 9 条
[1]   EFFICIENT STRING MATCHING - AID TO BIBLIOGRAPHIC SEARCH [J].
AHO, AV ;
CORASICK, MJ .
COMMUNICATIONS OF THE ACM, 1975, 18 (06) :333-340
[2]   FAST STRING SEARCHING ALGORITHM [J].
BOYER, RS ;
MOORE, JS .
COMMUNICATIONS OF THE ACM, 1977, 20 (10) :762-772
[3]  
Coit CJ, 2001, DISCEX'01: DARPA INFORMATION SURVIVABILITY CONFERENCE & EXPOSITION II, VOL I, PROCEEDINGS, P367, DOI 10.1109/DISCEX.2001.932231
[4]  
FISK M, 2001, CS20010670 CALTECH D
[5]  
GRAF I, RESULTS 1998 OFFLINE
[6]   NIDS - Pattern search vs. protocol decode [J].
Graham, R .
COMPUTERS & SECURITY, 2001, 20 (01) :37-41
[7]   Stateful intrusion detection for high-speed networks [J].
Kruegel, C ;
Valeur, F ;
Vigna, G ;
Kemmerer, R .
2002 IEEE SYMPOSIUM ON SECURITY AND PRIVACY, PROCEEDINGS, 2002, :285-293
[8]  
ROESCH M, 1999, KP LISA 99, P229
[9]   ADAPTIVE PATTERN-MATCHING [J].
SEKAR, RC ;
RAMESH, R ;
RAMAKRISHNAN, IV .
SIAM JOURNAL ON COMPUTING, 1995, 24 (06) :1207-1234