Performance Comparison and Detection Analysis in Snort and Suricata Environment

Performance Comparison and Detection Analysis in Snort and Suricata Environment
复制标题

DOI:
10.1007/s11277-016-3209-9
复制
发表时间:
2016-02
影响因子:
2.2
通讯作者:
W. Park;Seongji Ahn
W. Park;Seongji Ahn
中科院分区:
计算机科学4区
文献类型:
--
作者:
W. Park;Seongji Ahn

文献摘要

被引文献

相似文献

最近,犯罪是由于在互联网上的黑客攻击,以针对个人和公司的财务.由于数字融合和无处不在的IT系统所导致的大量犯罪,需要处理的网络数据包的数量明显增加。数字化融合和无处不在的IT系统使得入侵检测系统处理数据包的能力比以往更强。Snort(2.x版)是一个领先的开源IDS,它有着悠久的历史,但由于它是在很久以前构建的,它有一些限制,不适合今天的需求。例如,它的处理单元是单线程的。另一方面,Suricara的建立是为了弥补Snort的这些缺点。为了覆盖由数字融合和无处不在的IT系统引起的大量数据包,Suricata具有在多线程环境中处理数据包的可用性。本文通过对Snort和Suricata的处理和检测速度的分析和比较,来决定哪一个在单线程和多线程环境下更好。
Recently, crimes are cause in the internet by hacking to target one’s and the companies financial. Due to the massive crimes that are caused by digital convergence and ubiquitous IT system, it is clear that the amount of network packet which need to be processed are rising. The digital convergence and ubiquitous IT system caused the IDS (Intrusion Detection System) to process packets more than the past. Snort (version 2.x) is a leading open source IDS which has a long history but since it was built a long time ago, it has several limitations which are not fit for today’s requirements. Such as, it’s processing unit is in single threading. On the other hand, Suricara was built to cover Snorts these disadvantages. To cover massive amount of packets which are caused by digital convergence and ubiquitous IT system Suricata’s have the availability to process packets in multi-threading environment. In this paper we have analyzed and compared Snort and Suricata’s processing and detection rate to decide which is better in single threading or multi-threading environment.