Design and Implementation of a Linux Kernel Based Intrusion Prevention System in Gigabit Network Using Commodity Hardware

  • Li Chi Feng*
  • , Chao Wei Huang
  • , Jian Kai Wang
  • *Corresponding author for this work

Research output: Chapter in Book/Report/Conference proceedingChapterpeer-review

Abstract

Due to the development of the Internet, much valuable information is stored in the networked computer or transmitted on the network. System and network security is more and more important than before. Intrusion detection system (IDS) is developed to monitor network and/or system activities for malicious or unwanted behavior. Intrusion Prevention System offer stronger protection. When an attack is detected, IPS can drop the offending packets while still allowing all other traffic to pass. Recently, the speed of backbone network has already reached Gbit-scale, the intrusion detection or prevention is more difficult than before. The price of the related products in the market is above two million new Taiwan dollars. In this paper, we design and implement an inkernel Intrusion Prevention System in Gigabit network using commodity hardware and Linux operating systems. Preliminary experiment results show that, our system outperforms traditional intrusion prevention system (snort inline) substantially. Besides, our system can reach the wire speed under a typical set of detection rules.

Original languageEnglish
Title of host publicationAdvances in Intelligent Systems and Applications - Volume 2
Subtitle of host publicationProceedings of the International Computer
EditorsChang Ruay-Shiung, Peng Sheng-Lung, Lin Chia-Chen
Pages101-109
Number of pages9
DOIs
StatePublished - 2013
Externally publishedYes

Publication series

NameSmart Innovation, Systems and Technologies
Volume21
ISSN (Print)2190-3018
ISSN (Electronic)2190-3026

Keywords

  • Gigabit Network
  • Intrusion Detection System
  • Intrusion Prevention System
  • Linux Kernel

Fingerprint

Dive into the research topics of 'Design and Implementation of a Linux Kernel Based Intrusion Prevention System in Gigabit Network Using Commodity Hardware'. Together they form a unique fingerprint.

Cite this