An Embedded NIDS with Multi-Core Aware Packet Capture for Multi-Gigabits Networks
Date Issued
2011
Date
2011
Author(s)
Hsu, Chia-Hao
Abstract
Network security has been a serious problem in the Internet. To face this issue, network intrusion detection tools have become indispensable for computer systems and network gateways. In this paper, according to the different hardware features on network interface card, we propose two kinds of multi-core aware packet capture modules, called Flow Ring and MCA Ring. Moreover, we propose an embedded, multi-core aware network intrusion detection system (NIDS), which has the following features: 1) It integrates different novel multi-core aware packet capture modules, the MCA Ring and Flow Ring, with an NIDS. 2) It exploits a zero-copy mechanism to remove the overheads of packet copy processing from the network interface driver to the NIDS application. 3) It uses the concept of process and IRQ affinity to enhance the processing speed. The performance of NIDS under different packet capture modules in multi-gigabits networks has also been analyzed and presented in this paper. The results show that our integrated multi-core aware modules and NIDS are effective for detecting network intrusion attacks in multi-gigabits networks.
Subjects
Linux kernel
NIDS
Ring Buffer
Multi-Gigabits Network
Packet Capture
Type
thesis
File(s)![Thumbnail Image]()
Loading...
Name
ntu-100-R98921048-1.pdf
Size
23.32 KB
Format
Adobe PDF
Checksum
(MD5):8ea255fd57b293ab08c9c05e423e3071
