Skip to main navigation Skip to search Skip to main content

Performance analysis of content matching intrusion detection systems

  • Foundation for Research and Technology-Hellas
  • University of Pennsylvania

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

39 Scopus citations

Abstract

Although Network Intrusion Detection Systems (nIDS) are widely used, there is limited understanding of how these systems perform in different settings and how they should be evaluated. This paper examines how nIDS performance is affected by traffic characteristics, rulesets, string matching algorithms and processor architecture. The analysis presented in this paper shows that nIDS performance is very sensitive to these factors. Evaluating a nIDS therefore requires careful consideration of a fairly extensive set of scenarios. Our results also highlight potential dangers with the use of workloads based on combining widely-available packet header traces with synthetic packet content as well as with the use of synthetic rulesets.

Original languageEnglish
Title of host publicationProceedings - 2004 International Symposium on Applications and the Internet (Saint 2004)
Pages208-215
Number of pages8
DOIs
StatePublished - 2004
EventProceedings - 2004 International Symposium on Applications and the Internet (Saint 2004) - Tokyo, Japan
Duration: Jan 26 2004Jan 30 2004

Publication series

NameProceedings - International Symposium on Applications and the Internet

Conference

ConferenceProceedings - 2004 International Symposium on Applications and the Internet (Saint 2004)
Country/TerritoryJapan
CityTokyo
Period01/26/0401/30/04

Keywords

  • Intrusion detection
  • Security
  • Workload characterization and generation

Fingerprint

Dive into the research topics of 'Performance analysis of content matching intrusion detection systems'. Together they form a unique fingerprint.

Cite this