Design of Traffic Distributor Based on IXP1200 for Network Intrusion Detection System

CHEN Jia,SI Tiange,DAI Yiqi
DOI: https://doi.org/10.3969/j.issn.1000-3428.2006.13.058
2006-01-01
Abstract:Intrusion detection technology is an indispensable way to keep the network safety. This paper proposes an intrusion detection system (IDS) framework based on network processor and detecting cluster. The possibility of functioning the distributor by IXP1200 and the key algorithms of the distributor are discussed. The result shows that the distributor can achieve a more than 1000Mbps data-capturing ability, and the load balance policy based on CAM is a satisfying trade-off on protecting the information integrity and reducing the computing complexity.
What problem does this paper attempt to address?