Towards Distributed Network Intrusion Prevention with Respect to QoS Requirements

Andreas Viktor Hess, Mathias Bohge · 2005

An Intrusion Prevention System (IPS) analyzes each packet for malicious content before forwarding it and drops packets that originate by an intruder. To do so, the IPS has to be physically integrated into the network and needs to process the actual packets that run through it, instead of processing copies of the packets at some place outside the network. Therefore, independent of the way they are built, all IPS share the same problem — a decrease in performance of the network they try to protect. Therefore, the main objective in improving IPS performance is to develop an architecture that minimizes the overall delay and maximizes the network’s throughput while ensuring a sufficient level of security.

Read the paper · More papers on PaperTik