PABCS: A Traffic Partition Algorithm for Parallel Intrusion Detection
Hai-Guang LAI,Hao HUANG,Jun-Yuan XIE
DOI: https://doi.org/10.3321/j.issn:0254-4164.2007.04.007
2007-01-01
Jisuanji Xuebao/Chinese Journal of Computers
Abstract:As the band of networks increases, the process speed of network-based intrusion detection systems (NIDSes) hardly keep up with the speed of networks. By arranging several sensors to deal with the traffic in parallel, the intrusion detection system's speed can be significantly increased. How to split the traffic to the sensors is the key problem of a parallel intrusion detection system. To resolve the problems, load balance, attack evidence keeping, and efficiency have to be concerned. Existing traffic partition algorithms cannot satisfy these requirements well, especially load balance, which directly affect the performance of a parallel intrusion detection system. A traffic partition algorithm called PABCS is proposed in the paper, which splits the traffic according to connections' states. PABCS provides better load balance than the usually used hash-based algorithm and guarantees that no attacks evidence for intrusion detection is lost after partition. Moreover, in the experiment, the algorithm's process speed reaches 1 Gbps.