Network Security White Papers

Performance Analysis of Content Matching Intrusion Detection Systems

Overview A central question in the design and evaluation of a network Intrusion Detection System (nIDS) is whether it is possible to define a practical, accurate and meaningful performance evaluation methodology. In this direction, it is examined how nIDS performance interacts with experiment parameters such as traffic characteristics, nIDS rulesets, string matching algorithms and processor architecture. The results indicate that nIDS performance is sensitive to the both packet and ruleset content, yet this sensitivity seems to be bounded, allowing to craft and experiment with synthetic traces and rulesets. These experiments also show that experiments on a single trace and processor architecture are likely to be misleading; effective nIDS evaluation therefore requires careful consideration of a fairly extensive set of scenarios.

Further White Paper Details
PublisherUniversity of Pennsylvania File FormatPDF
Date PublishedNovember 2003
FormatWhite Papers   
Topics

Quick Sitemap Links: