Parallelization of Network Intrusion Detection Systems under Attack Conditions

2014 
Intrusion detection systems are proven remedies to protect networks and end systems in practice. IT systems, however, are currently changing their characteristics. Highly variable communication relations and constantly increasing network bandwidths force single intrusion detection instances to handle high peak rates. Today’s intrusion detection systems are not prepared to this development. In particular, they do not scale efficiently enough during an attack. In this article, we investigate different strategies how intrusion detection systems can cope with dynamic communication relations and increasing data rates under attack conditions. Based on a detailed performance profiling of typical intrusion detection systems, we outline the drawbacks of current optimization approaches and present a new approach for parallelizing the intrusion detection analysis that copes with the increasing network dynamics.
    • Correction
    • Source
    • Cite
    • Save
    • Machine Reading By IdeaReader
    22
    References
    4
    Citations
    NaN
    KQI
    []