A High-Performance Clustering Scheme with Application in Network Intrusion Prevention System
Journal
the 7th IEEE International Symposium on Communications and Information Technologies
Pages
1219-1224
Date Issued
2007-10
Author(s)
Chien-Hua Chiu
Abstract
As network security gains more and more attention, network intrusion prevention systems (NIPS) gradually become one of the most important network systems used in modern Internet environment. The demand for high performance NIPS is driven by the growing bandwidth available in the last mile WAN linkx as well as the increasing complexity of packet inspection. In this paper, we propose an adaptive clustering scheme to scale the throughput of in-line devices. The proposed scheme aggregates the processing power of multiple in-line devices in a cluster by making incominh traffic self-dispatched in a transparent fashion, and incorporates a traffic redsitribution mechanism that keeps the load of each device balanced. The cluster is also able to tolerate device failures so that devices in the cluster can be inserted or removed while the system is running. Bases on the designed architecture, we deploy snort, which is well-known and popular posed mechanisms as kernel modules over emebedded Linux. According to he results of performance evaluation, we successfully build a high performance, load balancing, and fault tolerant NIPS by means of the proposed mechanisms over the designed in-line device cluster.
Type
conference paper
