arrow
返回

A dynamic and scalable parallel Network Intrusion Detection System using intelligent rule ordering and Network Function Virtualization

delete2021-11-01
delete9
delete
OA
AI
H
Hårek Haugerud *
H
Huy Nhut Tran
N
Nadjib Aitsaadi
A
Anis Yazidi
DOI:10.1016/j.future.2021.05.037delete
delete原文链接
delete分享
delete收藏
查看原文
摘要

摘要

En 中文
A Network Intrusion Detection System (NIDS) is a fundamental security tool. However, under heavy network traffic, a NIDS might become a bottleneck. In an overloaded state, incoming and outgoing packets in the network might suffer from long delays since previous packets are still being inspected, and eventually the NIDS starts to drop packets when it runs out of hardware resources. Although many solutions have been suggested in the literature to counter this problem, they are not completely reliable as each of them has limitations. This paper investigates the design of a lightweight elastic architecture which allows parallel processing in an existing NIDS while maintaining the filtering integrity. Furthermore, we propose two adaptive algorithms which dynamically adjust and divide the signature rules evenly across NIDS nodes using a node level parallelism method in order to achieve intelligent rule ordering. We test our approaches in real-life settings by implementing a functioning prototype involving different modern networking technologies. The prototype presented is a Network Function Virtualization (NFV) of an intrusion detection system which utilizes Open vSwitch and Docker containers running Snort in order to provide an elastic system. To the best of our knowledge, there has been no work that orchestrates both scaling and rule splitting and re-ordering of IDS signatures as a part of a holistic elastic IDS solution. The results of this study show that the proposed algorithms are able to equally split the IDS workload and thereby enabling the system to scale by adjusting the number of virtual components which analyse the network traffic. At the same time the experiments indicate that the algorithms can be tuned by a single parameter in order to avoid that some packets go unexamined while simultaneously craving a minimum of the dynamically available computer resources. (C) 2021 The Authors. Published by Elsevier B.V.
Keyword:
Network Intrusion Detection Systems (NIDS)
Elastic architecture
Rule distribution
Network Function Virtualization (NFV)
AI总结

AI总结

对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。

期刊

F
Future Generation Computer Systems-The International Journal of eScience
IF:
6.1
论文数:
6.8K
被引数:
2.3W

机构

O
oslo metropolitan university (oslomet)
学者数:
2.4K
论文数: 2.3K
被引数: 3
U
Universite Paris Saclay
学者数:
7.3W
论文数: 5.3W
被引数: 540
引用论文

引用论文

Accelerating Pattern Matching Using a Novel Parallel Algorithm on GPUs
err2013-10-01
err68
PREAI
errLin, Cheng-Hung; Liu, Chen-Hsiung; Chien, Lung-Sheng; Chang, Shih-Chieh
err分享
err收藏
NFV Data Centers: A Systematic Review
err2020-01-01
err14
errOAAI
errSouza, Rafael; Dias, Kelvin; Fernandes, Stenio
err分享
err收藏
η2-Cyclo-octatetraene: crystal and molecular structure of[Mn(CO)22-C8H8)(η5-C5H5)]
err1977-01-01
err0
PREAI
errIan B. Benson; Selby A. R. Knox; Robert F. D. Stansfield; Peter Woodward
err分享
err收藏
An active splitter architecture for intrusion detection and prevention
err2006-01-01
err38
PREAI
errXinidis, K; Charitakis, I; Antonatos, S; Anagnostakis, KG; Markatos, EP
err分享
err收藏
Integrated NFV/SDN Architectures: A Systematic Literature Review
err2019-02-04
err102
PREAI
errBonfim, Michel S.; Dias, Kelvin L.; Fernandes, Stenio F. L.
err分享
err收藏
学者 查看更多内容