TY - GEN
T1 - MIDeA
T2 - 18th ACM Conference on Computer and Communications Security, CCS'11
AU - Vasiliadis, Giorgos
AU - Polychronakis, Michalis
AU - Ioannidis, Sotiris
PY - 2011
Y1 - 2011
N2 - Network intrusion detection systems are faced with the challenge of identifying diverse attacks, in extremely high speed networks. For this reason, they must operate at multi-Gigabit speeds, while performing highly-complex per-packet and per-flow data processing. In this paper, we present a multi-parallel intrusion detection architecture tailored for high speed networks. To cope with the increased processing throughput requirements, our system parallelizes network traffic processing and analysis at three levels, using multi-queue NICs, multiple CPUs, and multiple GPUs. The proposed design avoids locking, optimizes data transfers between the different processing units, and speeds up data processing by mapping different operations to the processing units where they are best suited. Our experimental evaluation shows that our prototype implementation based on commodity off-the-shelf equipment can reach processing speeds of up to 5.2 Gbit/s with zero packet loss when analyzing traffic in a real network, whereas the pattern matching engine alone reaches speeds of up to 70 Gbit/s, which is an almost four times improvement over prior solutions that use specialized hardware.
AB - Network intrusion detection systems are faced with the challenge of identifying diverse attacks, in extremely high speed networks. For this reason, they must operate at multi-Gigabit speeds, while performing highly-complex per-packet and per-flow data processing. In this paper, we present a multi-parallel intrusion detection architecture tailored for high speed networks. To cope with the increased processing throughput requirements, our system parallelizes network traffic processing and analysis at three levels, using multi-queue NICs, multiple CPUs, and multiple GPUs. The proposed design avoids locking, optimizes data transfers between the different processing units, and speeds up data processing by mapping different operations to the processing units where they are best suited. Our experimental evaluation shows that our prototype implementation based on commodity off-the-shelf equipment can reach processing speeds of up to 5.2 Gbit/s with zero packet loss when analyzing traffic in a real network, whereas the pattern matching engine alone reaches speeds of up to 70 Gbit/s, which is an almost four times improvement over prior solutions that use specialized hardware.
KW - Acceleration
KW - GPU
KW - Intrusion detection
KW - NIDS
KW - Pattern matching
UR - https://www.scopus.com/pages/publications/80755187805
U2 - 10.1145/2046707.2046741
DO - 10.1145/2046707.2046741
M3 - Conference contribution
AN - SCOPUS:80755187805
SN - 9781450310758
T3 - Proceedings of the ACM Conference on Computer and Communications Security
SP - 297
EP - 308
BT - CCS'11 - Proceedings of the 18th ACM Conference on Computer and Communications Security
Y2 - 17 October 2011 through 21 October 2011
ER -