• DocumentCode
    519637
  • Title

    Design and analysis of heartbeat protocol in NIDS cluster

  • Author

    Huang, Wei ; Wei, Gengyu ; Hu, Nan ; Yang, Yixian

  • Author_Institution
    Key Lab. of Network & Inf. Attack & Defense Technol. of MOE, BUPT, Beijing, China
  • Volume
    2
  • fYear
    2010
  • fDate
    21-24 May 2010
  • Abstract
    Heartbeat mechanism is widely used in designing high availability distributed system, while publish-subscribe architectural style has recently emerged as a promising approach to build a NIDS cluster with high dynamism and plenty of computational resources. In comparison with the requirements of general distributed computing, frontend in NIDS cluster cannot redistribute tasks on nodes failure and parallel stateful intrusion detection additionally requires the integrity of received session packets on analyzers. Therefore, the contradictory requirements of immediate node failure notification and infrequent analyzer status variation should be both considered. In this contribution, we designed one heartbeat protocol with four variations in publish-subscribe framework. By applying probabilistic model checking on the proposed heartbeat protocol, uptime ratio of one node in different variations is computed and compared under different setups. Suggestions on how to choose a suitable heartbeat for a NIDS cluster is described as well.
  • Keywords
    message passing; middleware; probability; security of data; NIDS cluster; distributed system; heartbeat protocol; immediate node failure notification; infrequent analyzer status variation; parallel stateful intrusion detection; probabilistic model checking; publish-subscribe architectural style; Algorithm design and analysis; Availability; Clustering algorithms; Distributed computing; Heart beat; Information analysis; Intrusion detection; Laboratories; Performance analysis; Protocols; NIDS cluster; PRISM; distributed computing; heartbeat; high availability; probabilistic model checking;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Future Computer and Communication (ICFCC), 2010 2nd International Conference on
  • Conference_Location
    Wuhan
  • Print_ISBN
    978-1-4244-5821-9
  • Type

    conf

  • DOI
    10.1109/ICFCC.2010.5497436
  • Filename
    5497436