Research on a High-Performance Intrusion Detecition Communication- Mechanismsupporting SMP

杨武,方滨兴,云晓春,张宏莉
DOI: https://doi.org/10.3321/j.issn:1000-436x.2004.01.013
2004-01-01
Abstract:The paper presents and implements a high-performance communication protocol architecture supporting SMP for the high bandwidth network intrusion detectionULNP(User Level Network Protocol). In ULNP, a user-level virtual network interface is designed by adopting a zero-copy method that bypasses the traditional kernel protocol stack from OS. In addition, the user-level TCP/IP protocol is optimized according to the characteristic of NIDS. So the communication overhead of NIDS is efficiently reduced. Experimental evaluation illustrates that compared with traditional NIDS, peak throughput of processing packets is increased by about 2-7 times and CPU idle ratio is increased by 1-2 times for the NIDS with ULNP in the high-speed network.
What problem does this paper attempt to address?