Improving network intrusion detection system performance through quality of service configuration and parallel technology

Intrusion detection system Parallel processing 0202 electrical engineering, electronic engineering, information engineering Quality of Service 006 Network security 02 engineering and technology Switch configuration Intrusion protection system
DOI: 10.1016/j.jcss.2014.12.012 Publication Date: 2014-12-19T20:53:46Z
ABSTRACT
This paper outlines an innovative software development that utilizes Quality of Service (QoS) and parallel technologies in Cisco Catalyst Switches to increase the analytical performance of a Network Intrusion Detection and Protection System (NIDPS) when deployed in highspeed networks. We have designed a real network to present experiments that use a Snort NIDPS. Our experiments demonstrate the weaknesses of NIDPSes, such as inability to process multiple packets and propensity to drop packets in heavy traffic and high-speed networks without analysing them. We tested Snort’s analysis performance, gauging the number of packets sent, analysed, dropped, filtered, injected, and outstanding. We suggest using QoS configuration technologies in a Cisco Catalyst 3560 Series Switch and parallel Snorts to improve NIDPS performance and to reduce the number of dropped packets. Our results show that our novel configuration improves performance.
SUPPLEMENTAL MATERIAL
Coming soon ....
REFERENCES (35)
CITATIONS (62)