Skip to main content
U.S. Department of Energy
Office of Scientific and Technical Information

The NIDS Cluster: Scalable, Stateful Network Intrusion Detection on Commodity Hardware

Conference ·
OSTI ID:935341

In this work we present a NIDS cluster as a scalable solution for realizing high-performance, stateful network intrusion detection on commodity hardware. The design addresses three challenges: (i) distributing traffic evenly across an extensible set of analysis nodes in a fashion that minimizes the communication required for coordination, (ii) adapting the NIDS's operation to support coordinating its low-level analysis rather than just aggregating alerts; and (iii) validating that the cluster produces sound results. Prototypes of our NIDS cluster now operate at the Lawrence Berkeley National Laboratory and the University of California at Berkeley. In both environments the clusters greatly enhance the power of the network security monitoring.

Research Organization:
Ernest Orlando Lawrence Berkeley National Laboratory, Berkeley, CA (US)
Sponsoring Organization:
Chemical Sciences Division
DOE Contract Number:
AC02-05CH11231
OSTI ID:
935341
Report Number(s):
LBNL-714E
Country of Publication:
United States
Language:
English

Similar Records

Network intrusion detector: NID user`s guide V 1.0
Technical Report · Thu Mar 31 23:00:00 EST 1994 · OSTI ID:10176285

Alerts Visualization and Clustering in Network-based Intrusion Detection
Conference · Thu Apr 01 00:00:00 EDT 2010 · OSTI ID:986833

Alerts Analysis and Visualization in Network-based Intrusion Detection Systems
Conference · Sun Aug 01 00:00:00 EDT 2010 · OSTI ID:986830