首页> 外文会议>Recent advances in intrusion detection >Predicting the Resource Consumption of Network Intrusion Detection Systems
【24h】

Predicting the Resource Consumption of Network Intrusion Detection Systems

机译:预测网络入侵检测系统的资源消耗

获取原文
获取原文并翻译 | 示例

摘要

When installing network intrusion detection systems (NIDSs), operators are faced with a large number of parameters and analysis options for tuning trade-offs between detection accuracy versus resource requirements. In this work we set out to assist this process by understanding and predicting the CPU and memory consumption of such systems. We begin towards this goal by devising a general NIDS resource model to capture the ways in which CPU and memory usage scale with changes in network traffic. We then use this model to predict the resource demands of different configurations in specific environments. Finally, we present an approach to derive site-specific NIDS configurations that maximize the depth of analysis given predefined resource constraints. We validate our approach by applying it to the open-source Bro NIDS, testing the methodology using real network data, and developing a corresponding tool, nidsconf, that automatically derives a set of configurations suitable for a given environment based on a sample of the site's traffic. While no automatically generated configuration can ever be optimal, these configurations provide sound starting points, with promise to significantly reduce the traditional trial-and-error NIDS installation cycle.
机译:在安装网络入侵检测系统(NIDS)时,操作员面临大量参数和分析选项,需要在检测精度与资源需求之间进行权衡取舍。在这项工作中,我们着手通过了解和预测此类系统的CPU和内存消耗来辅助此过程。我们通过设计通用的NIDS资源模型来开始实现此目标,以捕获CPU和内存使用量随网络流量变化而扩展的方式。然后,我们使用此模型来预测特定环境中不同配置的资源需求。最后,我们提出了一种方法,可以在特定的资源限制下,导出特定于站点的NIDS配置,该配置可以最大化分析深度。我们通过将其应用于开源Bro NIDS,使用真实网络数据测试方法并开发相应的工具nidsconf来验证我们的方法,该工具可根据站点样本自动得出适用于给定环境的一组配置。交通。尽管没有自动生成的配置可以达到最佳,但这些配置提供了良好的起点,有望大大缩短传统的试错NIDS安装周期。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号