Network Security White Papers
Design and Implementation of a High-Performance Network Intrusion Prevention System
Overview Network intrusion prevention systems provide proactive defense against security threats by detecting and blocking attack-related traffic. This task can be highly complex, and therefore, software-based network intrusion prevention systems have difficulty in handling high speed links. This paper describes the design and implementation of a high-performance network intrusion prevention system that combines the use of software-based network intrusion prevention sensors and a network processor board. The network processor acts as a customized load balancing splitter that cooperates with a set of modified content-based network intrusion detection sensors in processing network traffic. The paper shows that the components of such a system, if co-designed, can achieve high performance, while minimizing redundant processing and communication.
| Publisher | University of Pennsylvania | File Format | |
|---|---|---|---|
| Date Published | February 2005 | ||
| Format | White Papers | ||
| Topics | |||



