kirancodes.me
To Proof Maintenance & Beyond!

Conservative vs. optimistic parallelization of stateful network intrusion detection

Derek L. Schuff, Yung Ryn Choe, Vijay S. Pai

Abstract

This paper presents two approaches to parallelizing the Snort network intrusion detection system (NIDS). One scheme parallelizes NIDS processing conservatively across independent network flows, while the other optimistically achieves intra-flow parallelism by exploiting the observation that certain intra-flow dependences are uncommon and may be ignored under certain circumstances. Both schemes achieve average speedup over 2 on four cores, with an average throughput over 1 Gbps on 5 traces tested.

Related papers