A high-performance network monitoring platform for intrusion detection

  • Authors:
  • Yang Wu;Xiao-Chun Yun

  • Affiliations:
  • Computer Network and Information Security Technique Research Center, Harbin Institute of Technology, Harbin, China;Computer Network and Information Security Technique Research Center, Harbin Institute of Technology, Harbin, China

  • Venue:
  • ICOIN'05 Proceedings of the 2005 international conference on Information Networking: convergence in broadband and mobile networking
  • Year:
  • 2005

Quantified Score

Hi-index 0.00

Visualization

Abstract

This paper presents and implements a high-performance network monitoring platform (HPNMP) for high bandwidth network intrusion detection system (NIDS). The traffic load on a single machine is heavily reduced in an operation mode of parallel cluster. An efficient user-level messaging mechanism is implemented and a multi-rule packet filter is built at user layer. The results of experiments indicate that HPNMP is capable of reducing the using rate of CPU while improving the efficiency of data collection in NIDS so as to save much more system resources for complex data analysis in NIDS. ...