Visible to the public Performance comparison and optimization of mainstream NIDS systems in offline mode based on parallel processing technology

TitlePerformance comparison and optimization of mainstream NIDS systems in offline mode based on parallel processing technology
Publication TypeConference Paper
Year of Publication2021
AuthorsZhou, Tianyang
Conference Name2021 2nd International Conference on Computing and Data Science (CDS)
KeywordsData Science, Instruction sets, Metrics, multicore computing security, Multicore processing, network intrusion detection, NIDS, parallel processing, performance comparison, pubcrawl, resilience, Resiliency, Scalability, Snort2, Snort3, Software algorithms, Suricata, System performance
AbstractFor the network intrusion detection system (NIDS), improving the performance of the analysis process has always been one of the primary goals that NIDS needs to solve. An important method to improve performance is to use parallel processing technology to maximize the usage of multi-core CPU resources. In this paper, by splitting Pcap data packets, the NIDS software Snort3 can process Pcap packets in parallel mode. On this basis, this paper compares the performance between Snort2, Suricata, and Snort3 with different CPU cores in processing different sizes of Pcap data packets. At the same time, a parallel unpacking algorithm is proposed to further improve the parallel processing performance of Snort3.
DOI10.1109/CDS52072.2021.00030
Citation Keyzhou_performance_2021