Improving the performance of signature-based network intrusion detection sensors by multi-threading

  • Authors:
  • Bart Haagdorens;Tim Vermeiren;Marnix Goossens

  • Affiliations:
  • TELE Group, ETRO Department, Vrije Universiteit Brussel, Brussels, Belgium;R&I, Alcatel Bell, Antwerp, Belgium;TELE Group, ETRO Department, Vrije Universiteit Brussel, Brussels, Belgium

  • Venue:
  • WISA'04 Proceedings of the 5th international conference on Information Security Applications
  • Year:
  • 2004

Quantified Score

Hi-index 0.00

Visualization

Abstract

Signature-based Network Intrusion Detection System (NIDS) sensors match network packets against a pre-configured set of intrusion signatures. Current implementations of NIDS sensors employ only a single thread of execution and as a consequence benefit very little from multi-processor hardware platforms. A multi-threaded sensor would allow more efficient and scalable exploitation of these multi-processor machines. We present in detail a number of novel designs for a multi-threaded NIDS sensor and provide performance evaluation figures for a number of multi-threaded implementations of the popular open-source Snort system.