跳到主要导航 跳到搜索 跳到主要内容

A fuzzy-based dynamic provision approach for virtualized network intrusion detection systems

  • Beihang University
  • University of Leeds

科研成果: 书/报告/会议事项章节会议稿件同行评审

摘要

With the increasing prevalence of virtualization and cloud technologies, virtual security appliances have emerged and become a new way for traditional security appliances to be rapidly distributed and deployed in IT infrastructure. However, virtual security appliances are challenged with achieving optimal performance, as the physical resource is shared by several virtual machines, and this issue is aggravated when virtualizing network intrusion detection systems (NIDS). In this paper, we proposed a novel approach named fuzzyVIDS, which enables dynamic resource provision for NIDS virtual appliance. In fuzzyVIDS, we use fuzzy model to characterize the complex relationship between performance and resource demands and we develop an online fuzzy controller to adaptively control the resource allocation for NIDS under varying network traffic. Our approach has been successfully implemented in the iVIC platform. Finally, we evaluate our approach by comprehensive experiments based on Xen hypervisor and Snort NIDS and the results show that the proposed fuzzy control system can precisely allocate resources for NIDS according to its resource demands, while still satisfying the performance requirements of NIDS.

源语言英语
主期刊名Advances in Computer Science and Information Technology - AST/UCMA/ISA/ACN 2010 Conferences, Joint Proceedings
115-128
页数14
DOI
出版状态已出版 - 2010
活动2nd International Conference on Advanced Science and Technology - Miyazaki, 日本
期限: 23 6月 201025 6月 2010

出版系列

姓名Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
6059 LNCS
ISSN(印刷版)0302-9743
ISSN(电子版)1611-3349

会议

会议2nd International Conference on Advanced Science and Technology
国家/地区日本
Miyazaki
时期23/06/1025/06/10

指纹

探究 'A fuzzy-based dynamic provision approach for virtualized network intrusion detection systems' 的科研主题。它们共同构成独一无二的指纹。

引用此