Research on applying Network processor to parallel intrusion detection system

Jia-chun LI,Ling ZHANG
DOI: https://doi.org/10.3321/j.issn:1000-436X.2006.z1.014
2006-01-01
Abstract:Nowadays it is hot and difficult to improve attack detection rate and processing capability of intrusion detection system on high-speed environment. Parallel IDS based on network processor (NPBPIDS) is researched and implemented in this paper. The following methods are incorporated to improve system performance: the first is the use of IXP2400 network processor, where the traffics are collected speedily and splitted so as to keep streams as evenly loaded as possible. Early filtering of no payload packets and session-oriented dynamic feedback load balancing algorithm are used in traffic splitter. The second is the use of host arrays where the content of traffics with payload are detected. The experimental results demonstrate that it is availability and feasibility.
What problem does this paper attempt to address?