Javascript must be enabled to continue!
Alamut: a high‐performance network intrusion detection system in support of virtualized environments
View through CrossRef
ABSTRACTOne of the benefits of virtualization technology is the provision of secure and isolated computing environments on a single physical machine. However, the use of virtual machines for this purpose often degrades the overall system performance that is due to emulation costs, for example, packet filtering on every virtual machine. To allow virtual machines to be favorably used as before for the provision of secure environments but with comparably less performance degradation, we propose a new architecture called Alamut in this paper for restructuring any typical network intrusion detection system (NIDS) to run in a Xen‐based virtual execution environment. In the proposed architecture, primitive mechanisms for implementing the security concerns of typical NIDSs such as signature matching are placed at the kernel level of driver domain (dom0), whereas security policies and management modules are kept in user space of that domain. Separation of mechanisms from policies allows network packets to be verified at the kernel level first hand more efficiently without requiring costly context switches to push them to user space for validation. In addition, system administrators can easily define new policies at user level and determine on which virtual machines these policies should be enforced. A proof‐of‐concept implementation of Alamut has been prototyped on the Xen hypervisor using Bro open‐source NIDS. Experimental results show approximately 3.5‐fold increase in the overall system performance when our prototype is run compared with when Bro is run. Results also show 19% improvement in network throughput. The comparison of Alamut with Snort with the same set of signatures and attacks shows that our prototyped NIDS has lower processor utilization and has captured more packets in heavy network loads. Copyright © 2013 John Wiley & Sons, Ltd.
Title: Alamut: a high‐performance network intrusion detection system in support of virtualized environments
Description:
ABSTRACTOne of the benefits of virtualization technology is the provision of secure and isolated computing environments on a single physical machine.
However, the use of virtual machines for this purpose often degrades the overall system performance that is due to emulation costs, for example, packet filtering on every virtual machine.
To allow virtual machines to be favorably used as before for the provision of secure environments but with comparably less performance degradation, we propose a new architecture called Alamut in this paper for restructuring any typical network intrusion detection system (NIDS) to run in a Xen‐based virtual execution environment.
In the proposed architecture, primitive mechanisms for implementing the security concerns of typical NIDSs such as signature matching are placed at the kernel level of driver domain (dom0), whereas security policies and management modules are kept in user space of that domain.
Separation of mechanisms from policies allows network packets to be verified at the kernel level first hand more efficiently without requiring costly context switches to push them to user space for validation.
In addition, system administrators can easily define new policies at user level and determine on which virtual machines these policies should be enforced.
A proof‐of‐concept implementation of Alamut has been prototyped on the Xen hypervisor using Bro open‐source NIDS.
Experimental results show approximately 3.
5‐fold increase in the overall system performance when our prototype is run compared with when Bro is run.
Results also show 19% improvement in network throughput.
The comparison of Alamut with Snort with the same set of signatures and attacks shows that our prototyped NIDS has lower processor utilization and has captured more packets in heavy network loads.
Copyright © 2013 John Wiley & Sons, Ltd.
Related Results
619. Pharmacokinetic-Pharmacodynamic (PK-PD) Target Attainment Analyses to Support Epetraborole Dose Selection for the Treatment of Patients with Mycobacterium avium Complex (MAC) Lung Disease
619. Pharmacokinetic-Pharmacodynamic (PK-PD) Target Attainment Analyses to Support Epetraborole Dose Selection for the Treatment of Patients with Mycobacterium avium Complex (MAC) Lung Disease
Abstract
Background
Epetraborole (EBO) is an orally available, bacterial leucyl transfer RNA synthetase inhibitor that concentra...
LB2306. Population Pharmacokinetic (PPK), Pharmacokinetic/Pharmacodynamic attainment (PTA), and Clinical Pharmacokinetic/Pharmacodynamic (PK/PD) Analyses for Sulbactam-Durlobactam (SUL-DUR) to Support Dose Selection for the Treatment of Acinetobacter baum
LB2306. Population Pharmacokinetic (PPK), Pharmacokinetic/Pharmacodynamic attainment (PTA), and Clinical Pharmacokinetic/Pharmacodynamic (PK/PD) Analyses for Sulbactam-Durlobactam (SUL-DUR) to Support Dose Selection for the Treatment of Acinetobacter baum
Abstract
Background
SUL-DUR is a β-lactam/β-lactamase inhibitor combination in development for the treatment of ABC infections, ...
593. Population Pharmacokinetic Model Development for Epetraborole and Mycobacterium avium Complex (MAC) Lung Disease Patients Using Data from Phase 1 and 2 Studies
593. Population Pharmacokinetic Model Development for Epetraborole and Mycobacterium avium Complex (MAC) Lung Disease Patients Using Data from Phase 1 and 2 Studies
Abstract
Background
Epetraborole (EBO), an orally available bacterial leucyl transfer RNA synthetase inhibitor with potent activ...
592. Impact of Elevated MIC Values on Echinocandin Pharmacokinetic-Pharmacodynamic (PK-PD) Candida glabrata Target Attainment (TA)
592. Impact of Elevated MIC Values on Echinocandin Pharmacokinetic-Pharmacodynamic (PK-PD) Candida glabrata Target Attainment (TA)
Abstract
Background
Given the increasing prevalence of non-albicans Candida species, including C. glabrata and C. auris, which h...
Development and application of biological intelligence technology in computer
Development and application of biological intelligence technology in computer
To study the development and application of biological intelligence technology in computers and realize high-precision network anomaly detection, a distributed intrusion detection ...
Analysis of a Fuzzy Based Intrusion Detection System in Wireless Ad Hoc Networks
Analysis of a Fuzzy Based Intrusion Detection System in Wireless Ad Hoc Networks
Technology and its growth is considerably enormous. This massive growth allows the opening of new fields of application in the domain of wireless networking and mobile ad-hoc netwo...
Coastal karst springs in the Mediterranean basin : study of the mechanisms of saline pollution at the Almyros spring (Crete), observations and modelling
Coastal karst springs in the Mediterranean basin : study of the mechanisms of saline pollution at the Almyros spring (Crete), observations and modelling
Abstract
Variations in salinity and flow rate in the aerial, naturally salty spring of Almyros of Heraklion on Crete were monitored during two hydrological cycles. W...
Assessment of Network & Processor Virtualization in Cloud Computing
Assessment of Network & Processor Virtualization in Cloud Computing
Cloud Computing is an emerging field in applied computer science. Cloud computing depends on virtualization, where a sole physical resource is virtualized into numerous virtual res...

