Smart Logic - Preventing Packet Loss in High Speed Network Intrusion Detection Systems

  • Ahsan Subhan
  • Monis Akhlaq
  • Faeiz Alserhani
  • Irfan U. Awan
  • John Mellor
  • Andrea J. Cullen
  • Pravin Mirchandani
Part of the Lecture Notes of the Institute for Computer Sciences, Social Informatics and Telecommunications Engineering book series (LNICST, volume 41)

Abstract

Network Intrusion Detection Systems (NIDS) have gained substantial importance in today’s network security infrastructure. The performance of these devices in modern day traffic conditions is however found limited. It has been observed that the systems could hardly stand effective for the bandwidth of few hundred mega bits per second. Packet drop has been considered as the major bottleneck in the performance. We have identified a strong performance limitation of an open source Intrusion Detection System (IDS), Snort in [1, 2]. Snort was found dependent on host machine configuration. The response of Snort under heavy traffic conditions has opened a debate on its implementation and usage. We have developed the Smart Logic component to reduce the impact of packet drop in NIDS when subjected to heavy traffic volume. The proposed architecture utilizes packet capturing techniques applied at various processing stages shared between NIDS and packet handling applications. The designed architecture regains the lost traffic by a comparison between the analysed packets and the input stream using Smart Logic. The recaptured packets are then re-evaluated by a serialized IDS mechanism thus reducing impact of packet loss incurred in the routine implementation. The designed architecture has been implemented and tested on a scalable and sophisticated test bench replicating modern day network traffic. Our effort has shown noticeable improvement in the performance of Snort and has significantly improved its detection capacity.

Keywords

Network intrusion detection systems network performance packet drop Snort serialization 

Preview

Unable to display preview. Download preview PDF.

Unable to display preview. Download preview PDF.

References

  1. 1.
    Alserhani, F., Akhlaq, M., Awan, I., Cullen, A., Mellor, J., Mirchandani, P.: Evaluating Intrusion Detection Systems in High Speed Networks. In: Fifth International Conference of Information Assurance and Security (IAS 2009), August 18-20. IEEE Computer Society, Xian (in press, 2009)Google Scholar
  2. 2.
    Alserhani, F., Akhlaq, M., et al.: Snort Performance Evaluation. In: Proceedings of Twenty Fifth UK Performance Engineering Workshop (UKPEW 2009), Leeds, UK, July 6-7 (2009)Google Scholar
  3. 3.
    Kazienko, P., Dorosz, P.: Intrusion detection systems (IDS) Part 2 - Classification; methods; techniques (2004)Google Scholar
  4. 4.
    Tessel, J.D., Young, S., Linder, F.: The Hackers Handbook. Auerbach Publications, New York (2004)Google Scholar
  5. 5.
    Krugel, C., Valeur, F., vigna, G., Kemmerer, R.: Stateful Intrusion Detection for High Speed Networks. In: Proceedings of IEEE Symposium on Security and Privacy, Oakland, CA, May 2002, pp. 285–293 (2002)Google Scholar
  6. 6.
    Fischini, L., Thapial, A.V., Cavallaro, L., Kruegel, C., Vigna, G.: A Parallel Architecture for Stateful, High-Speed Intrusion Detection. In: Proceedings of fourth International Conference on Information system security, Hyderabad, India, pp. 203–220 (2008)Google Scholar
  7. 7.
    Xinidis, K., Charitakis, I., Antonatos, S., Anagnostakis, K.G., Markatos, E.P.: An Active Splitter Architecture for Intrusion Detection and Prevention. IEEE Trans. Dependable Sec. Computer 3(1), 31–44 (2006)CrossRefGoogle Scholar
  8. 8.
  9. 9.
  10. 10.
    Baker, A.R., Esler, J.: Snort IDS and IPS Toolkit, Syngress, Canada (2007)Google Scholar
  11. 11.
  12. 12.
  13. 13.
    VB.net, http://vb.net
  14. 14.
  15. 15.
  16. 16.
  17. 17.
  18. 18.
  19. 19.

Copyright information

© ICST Institute for Computer Science, Social Informatics and Telecommunications Engineering 2010

Authors and Affiliations

  • Ahsan Subhan
    • 1
  • Monis Akhlaq
    • 1
  • Faeiz Alserhani
    • 1
  • Irfan U. Awan
    • 1
  • John Mellor
    • 1
  • Andrea J. Cullen
    • 1
  • Pravin Mirchandani
    • 1
    • 2
  1. 1.Informatics Research InstituteUniversity of BradfordBradfordUnited Kingdom
  2. 2.Syphan Technologies (www.Syphan.com)India

Personalised recommendations