High Speed NIDS Design Based on GPU

LU Yongjing,WANG Dong
DOI: https://doi.org/10.3778/j.issn.1002-8331.2011.33.023
2011-01-01
Computer Engineering and Applications Journal
Abstract:With the continuous increase in network bandwidth and the capacity constraints,the traditional Network Intrusion Detection Systems(NIDS) is facing challenges.How to improve the efficiency of NIDS in high-speed network environment is facing challenges.Specially designed acceleration hardware is used to improve the detection rate,which is not only of high costs and inflexibility,but also only applicable to special institutions and not suitable to a large-scale popularization and promo-tion.An NIDS is presented based on the Snort opensource that exploits the powerful high-performance of GPU parallel processing capability,combining with the optimized Linux networking stack and multiple threads of Snort,and a high-performance soft-ware intrusion detection structure is designed.The experimental results show that GPU is very suitable for high speed network.
What problem does this paper attempt to address?