A Multi-core Supported Intrusion Detection System

作者:Tian Daxin*; Xiang Yang
来源:IFIP International Conference on Network and Parallel Computing, 2008-10-18 to 2008-10-21.
DOI:10.1109/NPC.2008.19

摘要

Integrated multi-core processors with on-chip application acceleration have established themselves as the most efficient method of powering next-generation networking platforms. New research has been conducted for addressing the issues of multi-core supported network and system security. This paper put forward an asymmetrical multiprocessing architecture multi-core supported anomaly intrusion detection system. The key idea is to use an independent core to run the intrusion detection system to monitor the host system. The detection method is based on the Hebb rule and uses libpcap to grab the network transmission packages. In the experiments, we use VMware which is configured to run the Ubuntu to simulate the IDS core. The results show that when the intrusion thereshold is 0.3-0.5 the system performs best.

全文