DocumentCode :
519637
Title :
Design and analysis of heartbeat protocol in NIDS cluster
Author :
Huang, Wei ; Wei, Gengyu ; Hu, Nan ; Yang, Yixian
Author_Institution :
Key Lab. of Network & Inf. Attack & Defense Technol. of MOE, BUPT, Beijing, China
Volume :
2
fYear :
2010
fDate :
21-24 May 2010
Abstract :
Heartbeat mechanism is widely used in designing high availability distributed system, while publish-subscribe architectural style has recently emerged as a promising approach to build a NIDS cluster with high dynamism and plenty of computational resources. In comparison with the requirements of general distributed computing, frontend in NIDS cluster cannot redistribute tasks on nodes failure and parallel stateful intrusion detection additionally requires the integrity of received session packets on analyzers. Therefore, the contradictory requirements of immediate node failure notification and infrequent analyzer status variation should be both considered. In this contribution, we designed one heartbeat protocol with four variations in publish-subscribe framework. By applying probabilistic model checking on the proposed heartbeat protocol, uptime ratio of one node in different variations is computed and compared under different setups. Suggestions on how to choose a suitable heartbeat for a NIDS cluster is described as well.
Keywords :
message passing; middleware; probability; security of data; NIDS cluster; distributed system; heartbeat protocol; immediate node failure notification; infrequent analyzer status variation; parallel stateful intrusion detection; probabilistic model checking; publish-subscribe architectural style; Algorithm design and analysis; Availability; Clustering algorithms; Distributed computing; Heart beat; Information analysis; Intrusion detection; Laboratories; Performance analysis; Protocols; NIDS cluster; PRISM; distributed computing; heartbeat; high availability; probabilistic model checking;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Future Computer and Communication (ICFCC), 2010 2nd International Conference on
Conference_Location :
Wuhan
Print_ISBN :
978-1-4244-5821-9
Type :
conf
DOI :
10.1109/ICFCC.2010.5497436
Filename :
5497436
Link To Document :
بازگشت