Title :
Design consideration of Network Intrusion detection system using Hadoop and GPGPU
Author :
Bandre, Sanraj Rajendra ; Nandimath, Jyoti N.
Author_Institution :
Dept. of Comput. Eng., Savitribai Phule Pune Univ., Pune, India
Abstract :
Modern computing has primarily shifted towards the distributed environment using commodity resources which results in increase in data and its security concern. This paper deals with design consideration of Network Intrusion Detection System (NIDS) based on the Hadoop framework and acceleration of its performance by using General Purpose Graphical Processing Unit (GPGPU). The large volume of data from an entire infrastructure is assigned to Hadoop framework and intrusion detections are carried out on GPGPU. This approach improves NIDS performance and it enables to provide quick response to various attacks on the network. In order to perform the general purposed computation on the GPU, NVidia provides the Compute Unified Device Architecture (CUDA) which is a parallel programming model which performs high-end complex operations using GPU. In order to process large volumes of data in distributed networks, Hadoop framework has to configure with various supporting ecosystems like Flume, Pig, Hive and HBase. These ecosystems enable the Hadoop framework to handle streaming data on the network and large log files on servers. The proposed system is capable of performing analytics over intrusion pattern and their behavior on the network, which helps a network administrator to configure network security policy and settings. Analytics over intrusion is done by using a Score-Weight approach called as Pattern Frequency Inverse Cluster Frequency (PF-ICF). The design consideration of accelerated NIDS is a solution towards the performance issues of various NIDS that faces due to the large volumes of the network traffic.
Keywords :
data analysis; graphics processing units; parallel architectures; parallel programming; security of data; CUDA; Compute Unified Device Architecture; Flume; GPGPU; HBase; Hadoop framework; Hive; NIDS; NVidia; PF-ICF; Pig; general purpose graphical processing unit; intrusion pattern analytics; log files; network intrusion detection system; network security policy; network traffic; parallel programming model; pattern frequency inverse cluster frequency; score-weight approach; streaming data handling; Algorithm design and analysis; Ecosystems; Graphics processing units; Intrusion detection; Servers; Telecommunication traffic; CUDA; GPGPU; Hadoop; NIDS; Network Security;
Conference_Titel :
Pervasive Computing (ICPC), 2015 International Conference on
Conference_Location :
Pune
DOI :
10.1109/PERVASIVE.2015.7087201