On the importance of header classification in HW/SW network intrusion detection systems

  • Authors:
  • Vassilis Dimopoulos;Giorgos Papadopoulos;Dionisios Pnevmatikatos

  • Affiliations:
  • Electronic and Computer Engineering Department, Technical University of Crete, Chania, Greece;Electronic and Computer Engineering Department, Technical University of Crete, Chania, Greece;Electronic and Computer Engineering Department, Technical University of Crete, Chania, Greece

  • Venue:
  • PCI'05 Proceedings of the 10th Panhellenic conference on Advances in Informatics
  • Year:
  • 2005

Quantified Score

Hi-index 0.00

Visualization

Abstract

In this paper we examine the impact of various levels of (partial) hardware acceleration levels on a software based Network Intrusion Detection System. While complete hardware solutions are possible and have been studied extensively, they are costly and may suffer from scalability and flexibility limitations. The flexibility of software is attractive to address these concerns. We show in this paper that (unexpectedly) a modest amount of hardware acceleration such as simple header classification can achieve respectable and cost-effective system throughput. We also find that further acceleration in the form of approximate filtering offers very small incremental improvement.