Design and Implementation of a High Performance Intrusion Prevention System

Xie Da-bin,Liang Gang
DOI: https://doi.org/10.3969/j.issn.1671-0428.2013.03.003
2013-01-01
Abstract:With the popularization of high-speed network,the traditional intrusion prevention system in high speed packet capture and real-time processing,has already can't meet the requirements of the performance.The paper proposed a kind of high performance intrusion prevention system,PF_RING DNA Intrusion Prevention System: PDIPS.PDIPS run on general multi-core platform,it used the PF_RING DNA technology to realize the packet capture in wire speed,at the same time,multithreading and CPU binding technology is used for parallel packets processing,to improve the overall performance.The test results show that under the same test environ-ment,PDIPS compared to traditional intrusion prevention scheme in performance has preferably improved,can adapt to the needs of the gigabit environment.
What problem does this paper attempt to address?