节点文献

高速网络入侵检测系统负载均衡策略与算法分析

Load balancing algorithm for high-speed network intrusion detection systems

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 蒋文保郝双戴一奇刘庭华

【Author】 JIANG Wenbao~(1,2),HAO Shuang~1,DAI Yiqi~1,LIU Tinghua~1(1.Department of Computer Science and Technology,Tsinghua University,Beijing 100084,China;2.Department of Inforation System,Beijing Information Technology Institute,Beijing 100101,China)

【机构】 清华大学计算机科学与技术系清华大学计算机科学与技术系 北京100084北京信息工程学院信息系统系北京100101北京100084

【摘要】 为了解决高速网络入侵检测系统(n IDS)的性能瓶颈问题,提出了可用于n IDS的负载均衡策略和算法。在阐述基于多引擎并行处理的n IDS框架的基础上,提出和分析了3种实用的n IDS负载均衡策略,重点论述了一种基于流的动态负载均衡算法——FDLB算法。该算法依据通过动态反馈和预测机制得到的当前引擎负载情况,以一个会话为分配单位,将新的网络数据包分发给当前负载最小的引擎。实验结果表明,在大流量多引擎情况下,FDLB算法的负载均衡效果要比轮转算法好得多。

【Abstract】 The performance of high-speed network intrusion detection systems(nIDSs) is improved by load balancing algorithms developed for high-speed nIDSs.Three load balancing policies were analyzed to develop a flow-based dynamic load balancing algorithm based on nIDSs using multiple detection engines.The algorithm divides the data stream according to the current value of each detection engine’s load using a dynamic feed and prediction mechanism.The incoming data packets for a new session are forwarded to the engine that currently has the lightest load.Test results show that the algorithm performs better than the Round Robin algorithm,especially when a large number of concurrent detection engines are used in heavy network traffic environments.

【基金】 国家自然科学基金资助项目(90304014)
  • 【文献出处】 清华大学学报(自然科学版) ,Journal of Tsinghua University(Science and Technology) , 编辑部邮箱 ,2006年01期
  • 【分类号】TP393.08
  • 【被引频次】57
  • 【下载频次】459
节点文献中: 

本文链接的文献网络图示:

本文的引文网络