A high-performance network monitoring platform for intrusion detection

Yang Wu,Xiao-Chun Yun
DOI: https://doi.org/10.1007/978-3-540-30582-8_6
2005-01-01
Abstract:This paper presents and implements a high-performance network monitoring platform (HPNMP) for high bandwidth network intrusion detection system (NIDS). The traffic load on a single machine is heavily reduced in an operation mode of parallel cluster. An efficient user-level messaging mechanism is implemented and a multi-rule packet filter is built at user layer. The results of experiments indicate that HPNMP is capable of reducing the using rate of CPU while improving the efficiency of data collection in NIDS so as to save much more system resources for complex data analysis in NIDS. ...
What problem does this paper attempt to address?