To search, Click below search items.


All Published Papers Search Service


A scalable distributed IDS Architecture for High speed Networks


Hassen Sallay, Khalid A. AlShalfan, Ouissem Ben Fred j


Vol. 9  No. 8  pp. 9-16


As networks become faster there is a need for security analysis techniques that can keep up with the increased network throughput. Traditional centralized approaches to traffic analysis cannot scale with the increase of bandwidth advances mainly due to their memory and computational requirements. In the last few years a number of distributed architectures have already been proposed for dedicated network monitoring tasks but they are not scalable in the context of high speed networks. In this paper we present an optimized scalable distributed architecture which is about 10 times quicker than the centralized architecture. The solution is based on switch-based splitting approach that supports intrusion detection on high-speed links by balancing the traffic load among different sensors running Snort.


Intrusion Detection, High Speed Networks, Distributed Architecture, Scalability