DocumentCode
2261546
Title
A high-performance clustering scheme with application in network intrusion prevention system
Author
Chiu, Chien-Hua ; Lin, Jung-Feng ; Lee, Jiunn-Jye ; Lei, Chin-Laung
Author_Institution
Nat. Taiwan Univ., Taipei
fYear
2007
fDate
17-19 Oct. 2007
Firstpage
1219
Lastpage
1224
Abstract
As network security gains more and more attention, network intrusion prevention systems (NIPS) gradually become one of the most important network systems used in modern Internet environment. The demand for high performance NIPS is driven by the growing bandwidth available in the last mile WAN links as well as the increasing complexity of packet inspection. In this paper, we propose an adaptive clustering scheme to scale the throughput of in-line devices. The proposed scheme aggregates the processing power of multiple in-line devices in a cluster by making incoming traffic self-dispatched in a transparent fashion, and incorporates a traffic redistribution mechanism that keeps the load of each device balanced. The cluster is also able to tolerate device failures so that devices in the cluster can be inserted or removed while the system is running. Based on the designed architecture, we deploy Snort, which is a well-known and popular NIPS, on each device of the cluster and implement all the proposed mechanisms as kernel modules over embedded Linux. According to the results of performance evaluation, we successfully build a high performance, load balancing, and fault tolerant NIPS by means of the proposed mechanisms over the designed in-line device cluster.
Keywords
Internet; Linux; security of data; telecommunication security; telecommunication traffic; NIPS; Snort; adaptive clustering scheme; embedded Linux; in-line device; network intrusion prevention system; traffic redistribution mechanism; Aggregates; Bandwidth; Fault tolerance; IP networks; Inspection; Kernel; Linux; Load management; Throughput; Wide area networks;
fLanguage
English
Publisher
ieee
Conference_Titel
Communications and Information Technologies, 2007. ISCIT '07. International Symposium on
Conference_Location
Sydney,. NSW
Print_ISBN
978-1-4244-0976-1
Electronic_ISBN
978-1-4244-0977-8
Type
conf
DOI
10.1109/ISCIT.2007.4392203
Filename
4392203
Link To Document