Skip to main content

New opportunities for load balancing in network-wide intrusion detection systems

Publication ,  Conference
Heorhiadi, V; Reiter, MK; Sekar, V
Published in: CoNEXT 2012 - Proceedings of the 2012 ACM Conference on Emerging Networking Experiments and Technologies
December 1, 2012

As traffic volumes and the types of analysis grow, network intrusion detection systems (NIDS) face a continuous scaling challenge. Management realities, however, limit NIDS hardware upgrades to occur typically once every 3-5 years. Given that traffic patterns can change dramatically, this leaves a significant scaling challenge in the interim. This motivates the need for practical solutions that can help administrators better utilize and augment their existing NIDS infrastructure. To this end, we design a general architecture for network-wide NIDS deployment that leverages three scaling opportunities: on-path distribution to split responsibilities, replicating traffic to NIDS clusters, and aggregating intermediate results to split expensive NIDS processing. The challenge here is to balance both the compute load across the network and the total communication cost incurred via replication and aggregation. We implement a backwards-compatible mechanism to enable existing NIDS infrastructure to leverage these benefits. Using emulated and trace-driven evaluations on several real-world network topologies, we show that our proposal can substantially reduce the maximum computation load, provide better resilience under traffic variability, and offer improved detection coverage. © 2012 ACM.

Duke Scholars

Altmetric Attention Stats
Dimensions Citation Stats

Published In

CoNEXT 2012 - Proceedings of the 2012 ACM Conference on Emerging Networking Experiments and Technologies

DOI

ISBN

9781450317757

Publication Date

December 1, 2012

Start / End Page

361 / 372
 

Citation

APA
Chicago
ICMJE
MLA
NLM
Heorhiadi, V., Reiter, M. K., & Sekar, V. (2012). New opportunities for load balancing in network-wide intrusion detection systems. In CoNEXT 2012 - Proceedings of the 2012 ACM Conference on Emerging Networking Experiments and Technologies (pp. 361–372). https://doi.org/10.1145/2413176.2413218
Heorhiadi, V., M. K. Reiter, and V. Sekar. “New opportunities for load balancing in network-wide intrusion detection systems.” In CoNEXT 2012 - Proceedings of the 2012 ACM Conference on Emerging Networking Experiments and Technologies, 361–72, 2012. https://doi.org/10.1145/2413176.2413218.
Heorhiadi V, Reiter MK, Sekar V. New opportunities for load balancing in network-wide intrusion detection systems. In: CoNEXT 2012 - Proceedings of the 2012 ACM Conference on Emerging Networking Experiments and Technologies. 2012. p. 361–72.
Heorhiadi, V., et al. “New opportunities for load balancing in network-wide intrusion detection systems.” CoNEXT 2012 - Proceedings of the 2012 ACM Conference on Emerging Networking Experiments and Technologies, 2012, pp. 361–72. Scopus, doi:10.1145/2413176.2413218.
Heorhiadi V, Reiter MK, Sekar V. New opportunities for load balancing in network-wide intrusion detection systems. CoNEXT 2012 - Proceedings of the 2012 ACM Conference on Emerging Networking Experiments and Technologies. 2012. p. 361–372.

Published In

CoNEXT 2012 - Proceedings of the 2012 ACM Conference on Emerging Networking Experiments and Technologies

DOI

ISBN

9781450317757

Publication Date

December 1, 2012

Start / End Page

361 / 372