The importance of security issues in network environments has increased greatly lately. Intrusion detection systems play an important role in network security environments. Nevertheless, nowadays, data network speed is so high that performing intrusion detection tasks becomes challenging. This paper presents a software architecture that intends to exploit the parallelism available on up-to-date and future workstations to apply intrusion detection rules in high speed networks. To achieve this, a shared memory multiprocessor system has been developed. The system includes a powerful rule language that adds big flexibility to the system.
Published in:
Security Technology, 2005. CCST '05. 39th Annual 2005 International Carnahan Conference on
Date of Conference: 11-14 Oct. 2005