Skip to main content

Network-wide deployment of intrusion detection and prevention systems

Publication ,  Conference
Sekar, V; Krishnaswamy, R; Gupta, A; Reiter, MK
Published in: Proceedings of the 6th International Conference on Emerging Networking Experiments and Technologies, Co-NEXT'10
December 1, 2010

Traditional efforts for scaling network intrusion detection (NIDS) and intrusion prevention systems (NIPS) have largely focused on a single-vantage-point view. In this paper, we explore an alternative design that exploits spatial, network-wide opportunities for distributing NIDS and NIPS functions. For the NIDS case, we design a linear programming formulation to assign detection responsibilities to nodes while ensuring that no node is overloaded. We describe a prototype NIDS implementation adapted from the Bro system to analyze traffic per these assignments, and demonstrate the advantages that this approach achieves. For NIPS, we show how to maximally leverage specialized hardware (e.g., TCAMs) to reduce the footprint of unwanted traffic on the network. Such hardware constraints make the optimization problem NP-hard, and we provide practical approximation algorithms based on randomized rounding. © 2010 ACM.

Duke Scholars

Published In

Proceedings of the 6th International Conference on Emerging Networking Experiments and Technologies, Co-NEXT'10

DOI

Publication Date

December 1, 2010
 

Citation

APA
Chicago
ICMJE
MLA
NLM
Sekar, V., Krishnaswamy, R., Gupta, A., & Reiter, M. K. (2010). Network-wide deployment of intrusion detection and prevention systems. In Proceedings of the 6th International Conference on Emerging Networking Experiments and Technologies, Co-NEXT’10. https://doi.org/10.1145/1921168.1921192
Sekar, V., R. Krishnaswamy, A. Gupta, and M. K. Reiter. “Network-wide deployment of intrusion detection and prevention systems.” In Proceedings of the 6th International Conference on Emerging Networking Experiments and Technologies, Co-NEXT’10, 2010. https://doi.org/10.1145/1921168.1921192.
Sekar V, Krishnaswamy R, Gupta A, Reiter MK. Network-wide deployment of intrusion detection and prevention systems. In: Proceedings of the 6th International Conference on Emerging Networking Experiments and Technologies, Co-NEXT’10. 2010.
Sekar, V., et al. “Network-wide deployment of intrusion detection and prevention systems.” Proceedings of the 6th International Conference on Emerging Networking Experiments and Technologies, Co-NEXT’10, 2010. Scopus, doi:10.1145/1921168.1921192.
Sekar V, Krishnaswamy R, Gupta A, Reiter MK. Network-wide deployment of intrusion detection and prevention systems. Proceedings of the 6th International Conference on Emerging Networking Experiments and Technologies, Co-NEXT’10. 2010.

Published In

Proceedings of the 6th International Conference on Emerging Networking Experiments and Technologies, Co-NEXT'10

DOI

Publication Date

December 1, 2010