DocumentCode :
655270
Title :
Network Intrusion Detection Systems in High-Speed Traffic in Computer Networks
Author :
Bulajoul, Waleed ; James, Ashish ; Pannu, Mohinder
Author_Institution :
Fac. of Eng. & Comput., Coventry Univ., Coventry, UK
fYear :
2013
fDate :
11-13 Sept. 2013
Firstpage :
168
Lastpage :
175
Abstract :
With the various and increasingly malicious attacks on networks and wireless systems, traditional security tools such as anti-virus programs and firewalls are not sufficient to provide free, integrated, reliable and secure networks. Intrusion detection systems (IDSs) are one of the most tested and reliable technologies to monitor incoming and outgoing network traffic to identify unauthorized usage and mishandling of computer system networks. It is critical to implement network intrusion detection systems (NIDSs) in computer networks that have high traffic and high-speed connectivity. Due to the fact that software NIDSs are still unable to detect all the growing threats to high-speed environments, such as flood attacks (UDP, TCP, ICMP and HTTP) or Denial and Distributed Denial of Service Attacks (DoS/DDoS), because the main function of these kinds of attacks is simply to send more traffic in high speed to systems to stop or slow down the performance of systems. Here we have designed a suitable real network to present experiments that use Snort NIDSs to demonstrate the weaknesses of NIDSs, such as its inability to process multiple packets at high speeds and its propensity to drop packets without analysing them. This paper outlines Snort NIDSs´ failures in high-speed and heavy traffic and its propensity to drop more packets as the speed and volume of traffic increase. We ran some consecutive tests to analyse the Snort performance using the number of packets received, the number of packets analysed, the number of packets filtered and the number of packets dropped. We suggest a parallel NIDS technology to reduce dropping packets as a solution.
Keywords :
computer network security; telecommunication traffic; DoS/DDoS; HTTP; ICMP; Snort NIDSs; Snort performance analysis; TCP; UDP; computer networks; distributed denial of service attacks; flood attacks; high-speed traffic; incoming network traffic monitoring; malicious attacks; network intrusion detection systems; outgoing network traffic monitoring; security tools; unauthorized usage identification; wireless systems; Computers; Intrusion detection; Monitoring; Protocols; Software; Telecommunication traffic; IDS; network security; open source;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
e-Business Engineering (ICEBE), 2013 IEEE 10th International Conference on
Conference_Location :
Coventry
Type :
conf
DOI :
10.1109/ICEBE.2013.26
Filename :
6686259
Link To Document :
بازگشت