Distributed Processing of Snort Alert Log using Hadoop

JeongJin Cheon, Tae-Young Choe · 2013

Snort is a famous tool for Intrusion Detection System (IDS), which is used to gather and analyse network packet in order to decide attacks through network. Until now, although processing a number of warning messages in real time, Snort is executed mainly in single computer systems. Unfortunately, current amount of network messages exceeds processing capacity of single computer systems. In order to embrace the huge amount of network messages, we have constructed a distributed IDS using Hadoop, HDFS, and 8 working nodes. Experimental results show that our distributed IDS has 426% performance compared to a single computer system. Keyword-Intrusion Detection System, Snort, Distributed Framework, Hadoop, HDFS

Read the paper · More papers on PaperTik