The Experts below are selected from a list of 6 Experts worldwide ranked by ideXlab platform
Kang Wang - One of the best experts on this subject based on the ideXlab platform.
-
a lightweight estimation algorithm to auto Configure Snort fast pattern matcher
2019 IEEE 44th LCN Symposium on Emerging Topics in Networking (LCN Symposium), 2019Co-Authors: Jiahai Yang, Kang WangAbstract:With the emergence of Network Function Virtualization (NFV) technology, researchers start to implement typical software Intrusion detection Systems (IDS) as Virtual Network Function (VNF) to improve the scalability of IDS deployment. Determining the setups and configurations of every instance to optimize VNF performance is one of the core challenges in NFV scenario. Previous researches mainly focus on how IDS performs under different Virtual Machine (VM) setups and just load its default configuration. However, when loading different rulesets and running IDS under different VM setups, the default configuration may not always lead to optimal performance. In this paper, we focus on the configuration problem of Snort. We propose a lightweight estimation algorithm to auto Configure the most performance-related part of Snort – Fast Pattern Matcher (FPM). We firstly explore how those options make influence on Snort’s packet detection by several measurement experiments. Then we summarize some basic principles to design our auto configuration algorithm. At last, we implement the algorithm to evaluate its accuracy and efficiency. The result shows our algorithm can seek a better configuration than the default one in various situations; in the meanwhile, it just takes a few seconds to run the algorithm, which is important if we want to import an auto configuration modular into NFV dynamic and elastic scheduling strategy.
Jiahai Yang - One of the best experts on this subject based on the ideXlab platform.
-
a lightweight estimation algorithm to auto Configure Snort fast pattern matcher
2019 IEEE 44th LCN Symposium on Emerging Topics in Networking (LCN Symposium), 2019Co-Authors: Jiahai Yang, Kang WangAbstract:With the emergence of Network Function Virtualization (NFV) technology, researchers start to implement typical software Intrusion detection Systems (IDS) as Virtual Network Function (VNF) to improve the scalability of IDS deployment. Determining the setups and configurations of every instance to optimize VNF performance is one of the core challenges in NFV scenario. Previous researches mainly focus on how IDS performs under different Virtual Machine (VM) setups and just load its default configuration. However, when loading different rulesets and running IDS under different VM setups, the default configuration may not always lead to optimal performance. In this paper, we focus on the configuration problem of Snort. We propose a lightweight estimation algorithm to auto Configure the most performance-related part of Snort – Fast Pattern Matcher (FPM). We firstly explore how those options make influence on Snort’s packet detection by several measurement experiments. Then we summarize some basic principles to design our auto configuration algorithm. At last, we implement the algorithm to evaluate its accuracy and efficiency. The result shows our algorithm can seek a better configuration than the default one in various situations; in the meanwhile, it just takes a few seconds to run the algorithm, which is important if we want to import an auto configuration modular into NFV dynamic and elastic scheduling strategy.
Hevier Marek - One of the best experts on this subject based on the ideXlab platform.
-
Implementácia IDS/IPS do prostredia univerzitnej siete MENDELU
2018Co-Authors: Hevier MarekAbstract:This diploma thesis deals with issue of IDS/IPS systems and possibilities of their utilization within the university network of Mendel University in Brno. The thesis includes a description how to install and Configure Snort IDS, including addon modules based on predefined parameters and the ability to detect malious traffic within college computer network of Mendel University in Brno. The results include verification of correct detection of selected attack types and the discussion of False Positive and False Negative