A Comparative Experimental Design and Performance Analysis of Snort-Based Intrusion Detection System in Practical Computer Networks

As one of the most reliable technologies, network intrusion detection system (NIDS) allows the monitoring of incoming and outgoing traffic to identify unauthorised usage and mishandling of attackers in computer network systems. To this extent, this paper investigates the experimental performance of...

Full description

Bibliographic Details
Main Authors: Imdadul Karim, Quoc-Tuan Vien, Tuan Anh Le, Glenford Mapp
Format: Article
Language:English
Published: MDPI AG 2017-02-01
Series:Computers
Subjects:
Online Access:http://www.mdpi.com/2073-431X/6/1/6
id doaj-f2e4e81f73c64b6ca3cc9abe22bae205
record_format Article
spelling doaj-f2e4e81f73c64b6ca3cc9abe22bae2052020-11-24T22:56:10ZengMDPI AGComputers2073-431X2017-02-0161610.3390/computers6010006computers6010006A Comparative Experimental Design and Performance Analysis of Snort-Based Intrusion Detection System in Practical Computer NetworksImdadul Karim0Quoc-Tuan Vien1Tuan Anh Le2Glenford Mapp3School of Science and Technology, Middlesex University, The Burroughs, London NW4 4BT, UKSchool of Science and Technology, Middlesex University, The Burroughs, London NW4 4BT, UKSchool of Science and Technology, Middlesex University, The Burroughs, London NW4 4BT, UKSchool of Science and Technology, Middlesex University, The Burroughs, London NW4 4BT, UKAs one of the most reliable technologies, network intrusion detection system (NIDS) allows the monitoring of incoming and outgoing traffic to identify unauthorised usage and mishandling of attackers in computer network systems. To this extent, this paper investigates the experimental performance of Snort-based NIDS (S-NIDS) in a practical network with the latest technology in various network scenarios including high data speed and/or heavy traffic and/or large packet size. An effective testbed is designed based on Snort using different muti-core processors, e.g., i5 and i7, with different operating systems, e.g., Windows 7, Windows Server and Linux. Furthermore, considering an enterprise network consisting of multiple virtual local area networks (VLANs), a centralised parallel S-NIDS (CPS-NIDS) is proposed with the support of a centralised database server to deal with high data speed and heavy traffic. Experimental evaluation is carried out for each network configuration to evaluate the performance of the S-NIDS in different network scenarios as well as validating the effectiveness of the proposed CPS-NIDS. In particular, by analysing packet analysis efficiency, an improved performance of up to 10% is shown to be achieved with Linux over other operating systems, while up to 8% of improved performance can be achieved with i7 over i5 processors.http://www.mdpi.com/2073-431X/6/1/6network securityintrusion detection systemSnortparallel processingnetwork traffic monitoringexperimental performance evaluation
collection DOAJ
language English
format Article
sources DOAJ
author Imdadul Karim
Quoc-Tuan Vien
Tuan Anh Le
Glenford Mapp
spellingShingle Imdadul Karim
Quoc-Tuan Vien
Tuan Anh Le
Glenford Mapp
A Comparative Experimental Design and Performance Analysis of Snort-Based Intrusion Detection System in Practical Computer Networks
Computers
network security
intrusion detection system
Snort
parallel processing
network traffic monitoring
experimental performance evaluation
author_facet Imdadul Karim
Quoc-Tuan Vien
Tuan Anh Le
Glenford Mapp
author_sort Imdadul Karim
title A Comparative Experimental Design and Performance Analysis of Snort-Based Intrusion Detection System in Practical Computer Networks
title_short A Comparative Experimental Design and Performance Analysis of Snort-Based Intrusion Detection System in Practical Computer Networks
title_full A Comparative Experimental Design and Performance Analysis of Snort-Based Intrusion Detection System in Practical Computer Networks
title_fullStr A Comparative Experimental Design and Performance Analysis of Snort-Based Intrusion Detection System in Practical Computer Networks
title_full_unstemmed A Comparative Experimental Design and Performance Analysis of Snort-Based Intrusion Detection System in Practical Computer Networks
title_sort comparative experimental design and performance analysis of snort-based intrusion detection system in practical computer networks
publisher MDPI AG
series Computers
issn 2073-431X
publishDate 2017-02-01
description As one of the most reliable technologies, network intrusion detection system (NIDS) allows the monitoring of incoming and outgoing traffic to identify unauthorised usage and mishandling of attackers in computer network systems. To this extent, this paper investigates the experimental performance of Snort-based NIDS (S-NIDS) in a practical network with the latest technology in various network scenarios including high data speed and/or heavy traffic and/or large packet size. An effective testbed is designed based on Snort using different muti-core processors, e.g., i5 and i7, with different operating systems, e.g., Windows 7, Windows Server and Linux. Furthermore, considering an enterprise network consisting of multiple virtual local area networks (VLANs), a centralised parallel S-NIDS (CPS-NIDS) is proposed with the support of a centralised database server to deal with high data speed and heavy traffic. Experimental evaluation is carried out for each network configuration to evaluate the performance of the S-NIDS in different network scenarios as well as validating the effectiveness of the proposed CPS-NIDS. In particular, by analysing packet analysis efficiency, an improved performance of up to 10% is shown to be achieved with Linux over other operating systems, while up to 8% of improved performance can be achieved with i7 over i5 processors.
topic network security
intrusion detection system
Snort
parallel processing
network traffic monitoring
experimental performance evaluation
url http://www.mdpi.com/2073-431X/6/1/6
work_keys_str_mv AT imdadulkarim acomparativeexperimentaldesignandperformanceanalysisofsnortbasedintrusiondetectionsysteminpracticalcomputernetworks
AT quoctuanvien acomparativeexperimentaldesignandperformanceanalysisofsnortbasedintrusiondetectionsysteminpracticalcomputernetworks
AT tuananhle acomparativeexperimentaldesignandperformanceanalysisofsnortbasedintrusiondetectionsysteminpracticalcomputernetworks
AT glenfordmapp acomparativeexperimentaldesignandperformanceanalysisofsnortbasedintrusiondetectionsysteminpracticalcomputernetworks
AT imdadulkarim comparativeexperimentaldesignandperformanceanalysisofsnortbasedintrusiondetectionsysteminpracticalcomputernetworks
AT quoctuanvien comparativeexperimentaldesignandperformanceanalysisofsnortbasedintrusiondetectionsysteminpracticalcomputernetworks
AT tuananhle comparativeexperimentaldesignandperformanceanalysisofsnortbasedintrusiondetectionsysteminpracticalcomputernetworks
AT glenfordmapp comparativeexperimentaldesignandperformanceanalysisofsnortbasedintrusiondetectionsysteminpracticalcomputernetworks
_version_ 1725654512489725952