• DocumentCode
    2563221
  • Title

    Performance analysis of content matching intrusion detection systems

  • Author

    Antonatos, S. ; Anagnostakis, K.G. ; Markatos, E.P. ; Polychronakis, M.

  • Author_Institution
    Inst. of Comput. Sci., Found. for Res. & Technol. - Hellas, Heraklio, Greece
  • fYear
    2004
  • fDate
    2004
  • Firstpage
    208
  • Lastpage
    215
  • Abstract
    Although network intrusion detection systems (nIDS) are widely used, there is limited understanding of how these systems perform in different settings and how they should be evaluated. This paper examines how nIDS performance is affected by traffic characteristics, rulesets, string matching algorithms and processor architecture. The analysis presented in this paper shows that nIDS performance is very sensitive to these factors. Evaluating a nIDS therefore requires careful consideration of a fairly extensive set of scenarios. Our results also highlight potential dangers with the use of workloads based on combining widely-available packet header traces with synthetic packet content as well as with the use of synthetic rulesets.
  • Keywords
    authorisation; computer networks; message authentication; performance evaluation; resource allocation; telecommunication security; content matching intrusion detection; network intrusion detection; network traffic; performance analysis; processor architecture; string matching algorithms; synthetic packet content; synthetic rulesets; workload characterization; workload generation; Algorithm design and analysis; Computational Intelligence Society; Computer science; Computer security; Costs; Intrusion detection; Laboratories; Performance analysis; Telecommunication traffic; Traffic control;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Applications and the Internet, 2004. Proceedings. 2004 International Symposium on
  • Print_ISBN
    0-7695-2068-5
  • Type

    conf

  • DOI
    10.1109/SAINT.2004.1266118
  • Filename
    1266118