• DocumentCode
    3246148
  • Title

    A parallel technique for improving the performance of signature-based network intrusion detection system

  • Author

    Shiri, Farzaneh Izak ; Shanmugam, Bharanidharan ; Idris, Norbik Bashah

  • Author_Institution
    Adv. Informatic Sch., Univ. Teknol. Malaysia, Kuala Lumpur, Malaysia
  • fYear
    2011
  • fDate
    27-29 May 2011
  • Firstpage
    692
  • Lastpage
    696
  • Abstract
    Nowadays, organizations discover that it is essential to protect their valuable information and internal resources from unauthorized access like deploying firewall. Firewall could prevent unauthorized access, but it cannot monitor network attacks. Another network security tool such as intrusion detection system is necessary to perform network activities monitoring. With the recent trend of high-speed networks, a large volume of data should be analyzed and processed with high-speed infrastructure. To promote the performance of network intrusion detection system and reduce the processing time of the traffic, present studies on network intrusion detection system for high-speed network focus on parallel techniques as an alternative. In this paper, a kind of parallelism is proposed to improve the performance of signature based intrusion detection system. The experimental results show that by the use of two signature based network intrusion detection systems running Snort in parallel with a portion of packets and a subset of rules, and distributing the traffic between them, the processing time of the traffic will be reduced. Consequently, the performance of the system will be improved.
  • Keywords
    authorisation; digital signatures; firewall; high-speed networks; internal resource protection; network activities monitoring; network security tool; parallel technique; signature-based network intrusion detection system; unauthorized access prevention; valuable information protection; Analytical models; Fires; Hardware; Internet; Local area networks; Logic gates; Servers; Function Paralle; Network Intrusion Detection System; Parallelism; Signature-based; nort;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Communication Software and Networks (ICCSN), 2011 IEEE 3rd International Conference on
  • Conference_Location
    Xi´an
  • Print_ISBN
    978-1-61284-485-5
  • Type

    conf

  • DOI
    10.1109/ICCSN.2011.6014986
  • Filename
    6014986