DocumentCode :
3670582
Title :
A linear programming scheme for IPS traffic scheduling
Author :
Jorge Crichigno;Nasir Ghani
Author_Institution :
College of Engineering and Technology, Northern New Mexico College, Espanola (NM), USA
fYear :
2015
fDate :
7/1/2015 12:00:00 AM
Firstpage :
16
Lastpage :
20
Abstract :
Intrusion Prevention System (IPS) sensors represent the initial security barrier of a network. A main challenge in today´s Internet environment is the amount of traffic these devices have to inspect. This paper presents a linear program for traffic scheduling in multi-sensor environments that alleviates inspection load at sensors. The model uses a per-flow alarm rate metric which quantifies the ratio of the amount of traffic that matches the configured signatures to the amount of traffic inspected. Traffic flows can be classified based on the metric, which permits the efficient use of computational resources to inspect suspicious traffic. Numerical results demonstrate how the proposed model can be used in enterprise networks. While the linear program is not constrained to integral solutions, traffic flows are mostly scheduled for inspection to a single sensor, which facilitates the collection of state information. This feature is essential to detect malicious traffic characterized by composite signatures.
Keywords :
"Inspection","Capacitive sensors","Measurement","Load management","Optimization","Approximation methods"
Publisher :
ieee
Conference_Titel :
Telecommunications and Signal Processing (TSP), 2015 38th International Conference on
Type :
conf
DOI :
10.1109/TSP.2015.7296216
Filename :
7296216
Link To Document :
بازگشت