期刊文献+

基于通用多核平台的入侵检测系统研究 被引量:1

Research on Intrusion Detection System Based on Commodity Multi-core Platform
下载PDF
导出
摘要 为应对网络流量快速增长问题,提出一种基于通用多核平台的入侵检测系统结构。在系统设计基础上,分析、验证了硬件平台、资源分配模式和流量特征等关键因素对系统处理性能的影响。实验表明,网络流量的流数、单位时间内报文包数等指标对系统性能的影响更大;在启用多核处理器超线程技术并将检测引擎与CPU绑定时,系统性能可以得到有效提高;系统易于实现,性价比高。 To deal with the rapid increment of network traffic, an Intrusion Detection System (IDS) based on commodity multi-core platform was proposed. This paper evaluated some critical factors for the system performance, such as hardware,resource-assigning and network traffic features. Extensive experiments demonstrate that number of traffic flow and pps index have larger impact on system performance. The ids performance can be improved obviously by activating the Hyper-Threading of multi-core processor and binding the detection engine with the CPU core. Our system is easy to be realized and has low price-performance ratio.
出处 《计算机科学》 CSCD 北大核心 2012年第3期71-74,共4页 Computer Science
基金 国家自然科学基金项目(61003303)资助
关键词 入侵检测 多核 超线程 Intrusion detection, Multi-core, Hyper-threading
  • 相关文献

参考文献12

  • 1CNNIC.中国互联网络发展状况统计报告[OL].http://www.cnnic.net.cn/dtygg/dtgg/201107/W020110719521725234632.pdf,2011.7.
  • 2Intel Core 2 Duo i7 [OL]. http://www, intel, com/zh_CN/products/processor/coreiT/index. htm, 2011.
  • 3Intel Xeon E7[OL]. http://www, intel, com/zh_CN/products/ server/processor/xeone7/index, htm, 2011.
  • 4INTEL. Supra-linear Packet Processing Performance with Intel? Multi-core Processors [OL]. http://www, intel, com/technology/advanced_eomm/311566, htm,2006.
  • 5Zhuang Z, Luo Y, Li M, et al. An Abstract Model for Intrusion Detection on Multi-Core Platform [C]///CHINAGRID ' 08. Washington, DC, USA: IEEE Computer Society, 2008 : 202-208.
  • 6Schuff D L, Choe Y R, Pai V S. Conservative vs. optimistic parallelization of stateful network intrusion detection[C]// PPoPP ' 07. New York, NY, USA: ACM, 2007 : 138-139.
  • 7Snort3. 0 [OL]. http://www, snort, org/snort-downloads/snortsp/, 2011.
  • 8Multi-core[OL]. http://www, intel, com/cn/technology/multi- eore/inde- htm, 2011.
  • 9Schuff D L, Pai V S,Willmann P, et al. Parallel Programmable Ethernet Controllers:Performance and Security [J]. Network, IEEE, 2007,21 (4) : 22-28.
  • 10Hyper-Threading [OL]. http://www, intel, com/cn/technology/ platform-technology/hyper-threading/index, htm, 2011.

同被引文献2

  • 1Wang Y,Lin C,Li Q L,et al.A queueing analysis for the denial of service(Do S)attacks in computer networks[J].Computer Networks,2007,51(12):3564-3573.
  • 2Jonsson E.An integrated framework for security and dependability[C]//Proceedings of the 1998 workshop on New security paradigms.ACM,1998:22-29.

引证文献1

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部