DocumentCode :
2307267
Title :
Characterizing sources and remedies for packet loss in network intrusion detection systems
Author :
Schaelicke, Lambert ; Freeland, J. Curt
Author_Institution :
Intel Corp., Santa Clara, CA, USA
fYear :
2005
fDate :
6-8 Oct. 2005
Firstpage :
188
Lastpage :
196
Abstract :
Network intrusion detection is becoming an increasingly important tool to protect critical information and infrastructure from unauthorized access. Network intrusion detection systems (NIDS) are commonly based on general-purpose workstations connected to a network tap. However, these general-purpose systems, although cost-efficient, are not able to sustain the packet rates of modern high-speed networks. The resulting packet loss degrades the system´s overall effectiveness, since attackers can intentionally overload the NIDS to evade detection. This paper studies the performance requirements of a commonly used open-source NIDS on a modern workstation architecture. Using full-system simulation, this paper characterizes the impact of a number of system-level optimizations and architectural trends on packet loss, and highlights the key bottlenecks for this type of network-intensive workloads. Results suggest that interrupt aggregation combined with rule set pruning is most effective in minimizing packet loss. Surprisingly, the workload also exhibits sufficient locality to benefit from larger level-2 caches as well. On the other hand, many other common architecture and system optimizations have only a negligible impact on throughput.
Keywords :
computer networks; performance evaluation; public domain software; security of data; telecommunication security; full-system simulation; interrupt aggregation; modern workstation architecture; open source network intrusion detection systems; packet loss minimization; rule set pruning; system-level optimization; Communication system control; Communication system traffic control; Computer science; High-speed networks; Intelligent networks; Intrusion detection; Telecommunication traffic; Throughput; Traffic control; Workstations;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Workload Characterization Symposium, 2005. Proceedings of the IEEE International
Print_ISBN :
0-7803-9461-5
Type :
conf
DOI :
10.1109/IISWC.2005.1526016
Filename :
1526016
Link To Document :
بازگشت