A High-Performance Network Intrusion Prevention System (2003)

Designing and implementing a high-performance network intrusion prevention system (for my master’s thesis). Network intrusion prevention systems provide proactive defense against security threats by detecting and blocking attack-related traffic. This task can be highly complex, and therefore, software-based network intrusion prevention systems are not capable of handling high speed links. Our system, called Digenis, combines the use of software-based network intrusion prevention sensors and a network processor board. The network processor acts as a customized load balancing splitter that cooperates with a set of modified content-based network intrusion detection sensors in processing network traffic. We show that the components of such a system, if co-designed, can achieve high performance, while minimizing redundant processing and communication. We have implemented the system using low-cost, off-the-shelf technology: an IXP1200 network processor evaluation board and commodity PCs. Our evaluation shows that our enhancements can reduce sensor load considerably, resulting in a system that can handle a fully-loaded Gigabit Ethernet link using a small number of sensors.

Publications and Reports

K. Xinidis, I. Charitakis, S. Antonatos, K. G. Anagnostakis, and E. P. Markatos. An Active Splitter Architecture for Intrusion Detection and Prevention. In IEEE Transactions on Dependable and Secure Computing, Vol. 3, No. 1, January-March 2006 [pdf]

K. G. Anagnostakis, S. Sidiroglou, P. Akritidis, K. Xinidis, E. P. Markatos and A. D. Keromytis. Detecting Targeted Attacks Using Shadow Honeypots. In Proceedings of the 14th USENIX Security Symposium, Baltimore, USA, August 1-5 2005 [pdf]

K. Xinidis, K. G. Anagnostakis and E. P. Markatos. Design and Implementation of a High-Performance Network Intrusion Prevention System. In Proceedings of the 20th International Information Security Conference (SEC 2005), Makuhari-Messe, Chiba, Japan, May 30 - June 1 2005 [pdf ppt]

K. Xinidis and E. P. Markatos. Network Intrusion Prevention on Multilevel Processing Architectures. Masters of Science (M.Sc.) Thesis, Dept. of Computer Science, University of Crete, October 2004 [pdf]

Further Information

For more information please visit Digenis project site

Motigo Webstats - Free web site statistics Personal homepage website counter
Free counter