Abstract
This document describes several design proposals to enhance net-work sensor performance on multiprocessor architectures. Our main contributions are related to the design of an autonomous sensor and to the idea of per-forming some parallelization of the analysis. These proposals can be implemented in network sensors such as intrusion detection systems, network antivirus appliances, QoS monitors and any other device based on network traffic analysing. Taking a certain model of traffic analysis as our starting point, we look deeply into some design proposals to address the difficulties involved in the parallelization. In this work, we propose a series of resources that can help us to solve these difficulties. Later, we study the prototypes developed in order to test different design alternatives and, finally, present selected case studies. We finish by quantitatively analysing the results to validate our design proposals.
Access this chapter
Tax calculation will be finalised at checkout
Purchases are for personal use only
Preview
Unable to display preview. Download preview PDF.
Similar content being viewed by others
References
Internet Security Systems: The Evolution of Intrusion Detection Technology. ISS Technical White Paper (August 29, 2001)
Snort Home Page: Lightweight Intrusion Detection System, http://www.snort.org
Prelude Home Page, http://www.prelude-ids.org/
Argus Home Page, http://www.qosient.com/argus/
Laing, B., Alderson, J., Rezabek, J., Bond, N.: How To Guide-Implementing a Network Based Intrusion Detection System. Internet Security Systems (2000)
Roesch, M.: Snort Users Manual. Snort Release: 1.8.3. Technical documentation (December 2001)
Internet Security Systems and Top Layer Networks: Gigabit Ethernet Intrusion Detection Solutions. Performance Test Results and Configuration Notes (July 2000)
Mell, P., Grance, T.: Guidelines to Federal Organizations on Use of the CVE Vulnerability Naming Scheme Within its Acquired Products and Information Technology Security Procedures. Recommendations of the National Institute of Standards and Technology (NIST) (January 2002)
Messmer, E.: Intrusion alert: Gigabit-speed intrusion-detection systems miss attacks on faster nets. Network World Fusion News (March 12, 2001)
Messmer, E.: More intrusion-detection options emerge. Network World Fusion News (November 11, 2001)
Author information
Authors and Affiliations
Editor information
Editors and Affiliations
Rights and permissions
Copyright information
© 2004 Springer-Verlag Berlin Heidelberg
About this paper
Cite this paper
Ferro, A., Liberal, F., Muñoz, A., Perfecto, C. (2004). Network Traffic Sensor for Multiprocessor Architectures: Design Improvement Proposals. In: Dini, P., Lorenz, P., de Souza, J.N. (eds) Service Assurance with Partial and Intermittent Resources. SAPIR 2004. Lecture Notes in Computer Science, vol 3126. Springer, Berlin, Heidelberg. https://doi.org/10.1007/978-3-540-27767-5_15
Download citation
DOI: https://doi.org/10.1007/978-3-540-27767-5_15
Publisher Name: Springer, Berlin, Heidelberg
Print ISBN: 978-3-540-22567-6
Online ISBN: 978-3-540-27767-5
eBook Packages: Springer Book Archive