DocumentCode :
3512549
Title :
QTL: An efficient scheduling policy for 10Gbps network intrusion detection system
Author :
Song, Bo ; Yang, Weibing ; Chen, Mingyu ; Zhao, Xiaofang ; Fan, Jianping
Author_Institution :
Inst. of Comput. Technol., Chinese Acad. of Sci., Beijing, China
fYear :
2010
fDate :
22-25 June 2010
Firstpage :
190
Lastpage :
195
Abstract :
Broad network bandwidth and deep inspection impose great challenge for the capability of 10Gpbs network security monitoring. Proper scheduling policies can improve system capability without requiring additional resources. LAS, a size-based scheduling policy which can achieve optimal mean response time by giving preferential analysis to short flows, is widely used in various aspects of network field. Due to the high variability property of Internet traffic, LAS favors short flows without penalizing large flows very much. Unfortunately, the inspection of large flows can not be guaranteed in those network intrusion detection systems on 10Gbps links, which are usually heavily loaded, or even overloaded. Although tiny in percentage, large flows comprise more than 50% of the total load, and therefore can not be ignored, especially when specified by users as critical. How to avoid starving large flows while still giving higher priority to short flows is a dilemma we have to face in practice. In this paper, we propose a QoS-supported three-level scheduling policy (QTL), which can remedy LAS´ defect. The experimental results show that our QTL scheduling policy has approximately the same performance as LAS for short flows, and meanwhile exhibits greatly enhanced processing capability for large flows.
Keywords :
Internet; quality of service; queueing theory; scheduling; security of data; Internet traffic; LAS; QTL; QoS-supported three-level scheduling policy; bit rate 10 Gbit/s; network intrusion detection system; network security monitoring; Inspection; Intrusion detection; Quality of service; Queueing analysis; Scheduling; Time factors; LAS; QoS-supported three-level scheduling (QTL); marked large flows; threat detection latency; threat loss rate;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Computers and Communications (ISCC), 2010 IEEE Symposium on
Conference_Location :
Riccione
ISSN :
1530-1346
Print_ISBN :
978-1-4244-7754-8
Type :
conf
DOI :
10.1109/ISCC.2010.5546727
Filename :
5546727
Link To Document :
بازگشت