学位论文详细信息
High Performance Network Intrusion Detection: A New Paradigm is Needed
intrusion detection;computer architecture;multicore;stream processing;click;bro;vespa;parallelism
Albrecht, David R. ; Borisov, Nikita ; Borisov ; Nikita
关键词: intrusion detection;    computer architecture;    multicore;    stream processing;    click;    bro;    vespa;    parallelism;   
Others  :  https://www.ideals.illinois.edu/bitstream/handle/2142/14658/Albrecht_David.pdf?sequence=2&isAllowed=y
美国|英语
来源: The Illinois Digital Environment for Access to Learning and Scholarship
PDF
【 摘 要 】

Fast data rates and complicated protocols have outpaced network intrusion detection systems. Administrators are forced to choose between breadth and depth: systems either deeply analyze traffic for a small handful of vulnerabilities, or search for many in parallel using more primitive (and easily evadable) techniques. We present a new parser architecture called VESPA, which uses the concept of vulnerability signatures to offer both speed and accuracy. VESPA is informed by a study of network protocols, which precedes the design. We conclude by reviewing several trends in computer architecture, and their impact on future intrusion detection systems. We believe a system which offers both speed and accuracy is possible, but requires rethinking how network intrusion detectors are designed, in light of trends in computer architecture.

【 预 览 】
附件列表
Files Size Format View
High Performance Network Intrusion Detection: A New Paradigm is Needed 338KB PDF download
  文献评价指标  
  下载次数:7次 浏览次数:23次