Dissecting NIDS Performance with Detailed Profiling

碩士 === 國立中正大學 === 資訊工程研究所 === 99 === Designing a high-speed NIDS (network intrusion detection system) has attracted much attention over recent years due to ever-increasing amount of network trac and ever-complicated attacks. Deeply studying the NIDS performance is an important step toward a high-spe...

Full description

Bibliographic Details
Main Authors: Lee,Jiahau, 李家豪
Other Authors: Lin,Poching
Format: Others
Language:en_US
Published: 2011
Online Access:http://ndltd.ncl.edu.tw/handle/62379745612344715808
id ndltd-TW-099CCU00392021
record_format oai_dc
spelling ndltd-TW-099CCU003920212015-10-28T04:06:35Z http://ndltd.ncl.edu.tw/handle/62379745612344715808 Dissecting NIDS Performance with Detailed Profiling 深度分析入侵偵測系統之效能 Lee,Jiahau 李家豪 碩士 國立中正大學 資訊工程研究所 99 Designing a high-speed NIDS (network intrusion detection system) has attracted much attention over recent years due to ever-increasing amount of network trac and ever-complicated attacks. Deeply studying the NIDS performance is an important step toward a high-speed design. This work studies how the NIDS performance can vary with input network traffic, in- cluding malicious trac, and system configuration, based on detailed pro- filing with two popular NIDSs, Snort and Bro. According to the profiling, we find analyzing the payloads (primarily pattern matching in Snort and executing the policy scripts in Bro) can dominate the execution time for most of packet traces. Moreover, connection tracking and packet reassembly can be also time-consuming if they are frequently invoked. Therefore, a ro- bust high-speed NIDS design can focus on improving payload analysis and preprocessing, particularly packet reassembly. We also demonstrated that aggregating the profiling results can be used to predict the results for bulk network traffic in a real environment. In other words, it is feasible to watch the composing traffic types in the bulk traffic and individually analyzing the sample of each type to extrapolate the performance for the total traffic. Lin,Poching 林柏青 2011 學位論文 ; thesis 40 en_US
collection NDLTD
language en_US
format Others
sources NDLTD
description 碩士 === 國立中正大學 === 資訊工程研究所 === 99 === Designing a high-speed NIDS (network intrusion detection system) has attracted much attention over recent years due to ever-increasing amount of network trac and ever-complicated attacks. Deeply studying the NIDS performance is an important step toward a high-speed design. This work studies how the NIDS performance can vary with input network traffic, in- cluding malicious trac, and system configuration, based on detailed pro- filing with two popular NIDSs, Snort and Bro. According to the profiling, we find analyzing the payloads (primarily pattern matching in Snort and executing the policy scripts in Bro) can dominate the execution time for most of packet traces. Moreover, connection tracking and packet reassembly can be also time-consuming if they are frequently invoked. Therefore, a ro- bust high-speed NIDS design can focus on improving payload analysis and preprocessing, particularly packet reassembly. We also demonstrated that aggregating the profiling results can be used to predict the results for bulk network traffic in a real environment. In other words, it is feasible to watch the composing traffic types in the bulk traffic and individually analyzing the sample of each type to extrapolate the performance for the total traffic.
author2 Lin,Poching
author_facet Lin,Poching
Lee,Jiahau
李家豪
author Lee,Jiahau
李家豪
spellingShingle Lee,Jiahau
李家豪
Dissecting NIDS Performance with Detailed Profiling
author_sort Lee,Jiahau
title Dissecting NIDS Performance with Detailed Profiling
title_short Dissecting NIDS Performance with Detailed Profiling
title_full Dissecting NIDS Performance with Detailed Profiling
title_fullStr Dissecting NIDS Performance with Detailed Profiling
title_full_unstemmed Dissecting NIDS Performance with Detailed Profiling
title_sort dissecting nids performance with detailed profiling
publishDate 2011
url http://ndltd.ncl.edu.tw/handle/62379745612344715808
work_keys_str_mv AT leejiahau dissectingnidsperformancewithdetailedprofiling
AT lǐjiāháo dissectingnidsperformancewithdetailedprofiling
AT leejiahau shēndùfēnxīrùqīnzhēncèxìtǒngzhīxiàonéng
AT lǐjiāháo shēndùfēnxīrùqīnzhēncèxìtǒngzhīxiàonéng
_version_ 1718111776677036032