Performance Enhancement of Snort IDS through Kernel Modification

Sabir Ali Changazi, Imran Shafi, Khaled Saleh, M. H. Islam, Syed Muzammil Hussainn, Atif Ali
{"title":"Performance Enhancement of Snort IDS through Kernel Modification","authors":"Sabir Ali Changazi, Imran Shafi, Khaled Saleh, M. H. Islam, Syed Muzammil Hussainn, Atif Ali","doi":"10.1109/ICICT47744.2019.9001286","DOIUrl":null,"url":null,"abstract":"Performance and improved packet handling capacity against high traffic load are important requirements for an effective intrusion detection system (IDS). Snort is one of the most popular open-source intrusion detection system which runs on Linux. This research article discusses ways of enhancing the performance of Snort by modifying Linux key parameters related to NAPI packet reception mechanism within the Linux kernel networking subsystem. Our enhancement overcomes the current limitations related to NAPI throughput. We experimentally demonstrate that current default budget B value of 300 does not yield the best performance of Snort throughput. We show that a small budget value of 14 gives the best Snort performance in terms of packet loss both at Kernel subsystem and at the application level. Furthermore, we compare our results to those reported in the literature, and we show that our enhancement through tuning certain parameters yield superior performance.","PeriodicalId":351104,"journal":{"name":"2019 8th International Conference on Information and Communication Technologies (ICICT)","volume":"89 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2019-11-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"4","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2019 8th International Conference on Information and Communication Technologies (ICICT)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICICT47744.2019.9001286","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 4

Abstract

Performance and improved packet handling capacity against high traffic load are important requirements for an effective intrusion detection system (IDS). Snort is one of the most popular open-source intrusion detection system which runs on Linux. This research article discusses ways of enhancing the performance of Snort by modifying Linux key parameters related to NAPI packet reception mechanism within the Linux kernel networking subsystem. Our enhancement overcomes the current limitations related to NAPI throughput. We experimentally demonstrate that current default budget B value of 300 does not yield the best performance of Snort throughput. We show that a small budget value of 14 gives the best Snort performance in terms of packet loss both at Kernel subsystem and at the application level. Furthermore, we compare our results to those reported in the literature, and we show that our enhancement through tuning certain parameters yield superior performance.
通过修改内核增强Snort IDS的性能
对于一个有效的入侵检测系统,性能和高流量负载下的数据包处理能力是一个重要的要求。Snort是在Linux上运行的最流行的开源入侵检测系统之一。本文讨论了通过修改Linux内核网络子系统中与NAPI数据包接收机制相关的Linux关键参数来增强Snort性能的方法。我们的增强克服了当前与NAPI吞吐量相关的限制。我们通过实验证明,当前默认预算B值为300并不能产生Snort吞吐量的最佳性能。我们表明,就内核子系统和应用程序级别的数据包丢失而言,较小的预算值为14可以提供最佳的Snort性能。此外,我们将我们的结果与文献中报道的结果进行了比较,并表明通过调整某些参数进行的增强产生了更好的性能。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信