{"id":{"repo_id":"uiuc","oai_identifier":"oai:www.ideals.illinois.edu:2142/14658"},"canonical_url":"https://search.dev.ndltd.org/etd/uiuc/oai:www.ideals.illinois.edu:2142/14658","repository":{"repo_id":"uiuc","name":"University of Illinois - Urbana-Champaign","base_url":"https://www.ideals.illinois.edu/oai-pmh"},"display":{"title":"High Performance Network Intrusion Detection: A New Paradigm is Needed","abstract":"Fast data rates and complicated protocols have outpaced network intrusion detection systems. Administrators are forced to choose between breadth and depth: systems either deeply analyze traﬃc for a small handful of vulnerabilities, or search for many in parallel using more primitive (and easily evadable) techniques. We present a new parser architecture called VESPA, which uses the concept of vulnerability signatures to oﬀer both speed and accuracy. VESPA is informed by a study of network protocols, which precedes the design. We conclude by reviewing several trends in computer architecture, and their impact on future intrusion detection systems. We believe a system which oﬀers both speed and accuracy is possible, but requires rethinking how network intrusion detectors are designed, in light of trends in computer architecture.","abstract_html":"Fast data rates and complicated protocols have outpaced network intrusion detection systems. Administrators are forced to choose between breadth and depth: systems either deeply analyze traﬃc for a small handful of vulnerabilities, or search for many in parallel using more primitive (and easily evadable) techniques. We present a new parser architecture called VESPA, which uses the concept of vulnerability signatures to oﬀer both speed and accuracy. VESPA is informed by a study of network protocols, which precedes the design. We conclude by reviewing several trends in computer architecture, and their impact on future intrusion detection systems. We believe a system which oﬀers both speed and accuracy is possible, but requires rethinking how network intrusion detectors are designed, in light of trends in computer architecture.","abstract_has_math":false,"creators":["Albrecht, David R."],"institution":"University of Illinois at Urbana-Champaign","degree_name":"M.S.","degree_level":"Thesis","degree_discipline":"Electrical & Computer Engr","degree_department":null,"school":null,"contributors":["Borisov, Nikita"],"advisors":[],"committee_chairs":[],"committee_members":[],"year":2010,"date_issued":"2010-01-06T16:20:41Z","date_published":"2010-01-06T16:20:41Z","updated_at":"2026-07-22T22:25:08Z","subjects":["intrusion detection","computer architecture","multicore","stream processing","click","bro","vespa","parallelism"],"languages":["en"],"rights":["Copyright 2009 David Albrecht."],"rights_urls":[],"identifier_entries":[]},"links":{"outbound_url":"http://hdl.handle.net/2142/14658","outbound_label":"Handle","outbound_source":"dc:identifier"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor","label":"Contributor","values":["Borisov, Nikita"]},{"key":"dc:creator","label":"Author","values":["Albrecht, David R."]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date","label":"Dc Date","values":["2010-01-06T16:20:41Z","2009-12"]},{"key":"thesis:degree_discipline","label":"Discipline","values":["Electrical & Computer Engr"]},{"key":"thesis:degree_level","label":"Degree Level","values":["Thesis"]},{"key":"thesis:degree_name","label":"Degree Name","values":["M.S."]},{"key":"thesis:institution_name","label":"Thesis Institution Name","values":["University of Illinois at Urbana-Champaign"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["intrusion detection","computer architecture","multicore","stream processing","click","bro","vespa","parallelism"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:language","label":"Dc Language","values":["en"]},{"key":"dc:rights","label":"Dc Rights","values":["Copyright 2009 David Albrecht."]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier","label":"Identifier","values":["http://hdl.handle.net/2142/14658"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description","label":"Description","values":["Fast data rates and complicated protocols have outpaced network intrusion detection systems. Administrators are forced to choose between breadth and depth: systems either deeply analyze traﬃc for a small handful of vulnerabilities, or search for many in parallel using more primitive (and easily evadable) techniques. We present a new parser architecture called VESPA, which uses the concept of vulnerability signatures to oﬀer both speed and accuracy. VESPA is informed by a study of network protocols, which precedes the design. We conclude by reviewing several trends in computer architecture, and their impact on future intrusion detection systems. We believe a system which oﬀers both speed and accuracy is possible, but requires rethinking how network intrusion detectors are designed, in light of trends in computer architecture.","Item withdrawn by Mark Zulauf (zulauf@illinois.edu) on 2009-12-08T22:32:24Z Item was in collections: University of Illinois Theses & Dissertations (ID: 1) No. of bitstreams: 1 Albrecht_David.pdf: 346170 bytes, checksum: 1ed49fadc9ff334664f25e8e6e94aa33 (MD5)","Made available in DSpace on 2010-01-06T16:20:41Z (GMT). No. of bitstreams: 2 license.txt: 4064 bytes, checksum: c3d9fa33bddfb790de023698a0b30ab1 (MD5) Albrecht_David.pdf: 346170 bytes, checksum: 1ed49fadc9ff334664f25e8e6e94aa33 (MD5)"]},{"key":"dc:title","label":"Title","values":["High Performance Network Intrusion Detection: A New Paradigm is Needed"]}]}],"canonical_facts":{"dc:contributor":["Borisov, Nikita"],"dc:creator":["Albrecht, David R."],"dc:date":["2010-01-06T16:20:41Z","2009-12"],"dc:description":["Fast data rates and complicated protocols have outpaced network intrusion detection systems. Administrators are forced to choose between breadth and depth: systems either deeply analyze traﬃc for a small handful of vulnerabilities, or search for many in parallel using more primitive (and easily evadable) techniques. We present a new parser architecture called VESPA, which uses the concept of vulnerability signatures to oﬀer both speed and accuracy. VESPA is informed by a study of network protocols, which precedes the design. We conclude by reviewing several trends in computer architecture, and their impact on future intrusion detection systems. We believe a system which oﬀers both speed and accuracy is possible, but requires rethinking how network intrusion detectors are designed, in light of trends in computer architecture.","Item withdrawn by Mark Zulauf (zulauf@illinois.edu) on 2009-12-08T22:32:24Z Item was in collections: University of Illinois Theses & Dissertations (ID: 1) No. of bitstreams: 1 Albrecht_David.pdf: 346170 bytes, checksum: 1ed49fadc9ff334664f25e8e6e94aa33 (MD5)","Made available in DSpace on 2010-01-06T16:20:41Z (GMT). No. of bitstreams: 2 license.txt: 4064 bytes, checksum: c3d9fa33bddfb790de023698a0b30ab1 (MD5) Albrecht_David.pdf: 346170 bytes, checksum: 1ed49fadc9ff334664f25e8e6e94aa33 (MD5)"],"dc:identifier":["http://hdl.handle.net/2142/14658"],"dc:language":["en"],"dc:rights":["Copyright 2009 David Albrecht."],"dc:subject":["intrusion detection","computer architecture","multicore","stream processing","click","bro","vespa","parallelism"],"dc:title":["High Performance Network Intrusion Detection: A New Paradigm is Needed"],"thesis:degree_discipline":["Electrical & Computer Engr"],"thesis:degree_level":["Thesis"],"thesis:degree_name":["M.S."],"thesis:institution_name":["University of Illinois at Urbana-Champaign"]},"updated_at":"2026-07-22T22:25:08Z"}