Back to results

University of Illinois at Urbana-Champaign

High Performance Network Intrusion Detection: A New Paradigm is Needed

Abstract

dc:description

Fast data rates and complicated protocols have outpaced network intrusion detection systems. Administrators are forced to choose between breadth and depth: systems either deeply analyze traffic for a small handful of vulnerabilities, or search for many in parallel using more primitive (and easily evadable) techniques. We present a new parser architecture called VESPA, which uses the concept of vulnerability signatures to offer both speed and accuracy. VESPA is informed by a study of network protocols, which precedes the design. We conclude by reviewing several trends in computer architecture, and their impact on future intrusion detection systems. We believe a system which offers both speed and accuracy is possible, but requires rethinking how network intrusion detectors are designed, in light of trends in computer architecture.

Degree

thesis:*
Name thesis:degree_name
M.S.
Level thesis:degree_level
Thesis
Discipline thesis:degree_discipline
Electrical & Computer Engr
Grantor
University of Illinois at Urbana-Champaign
Year dc:date
2010

Author and committee

dc:creator, dc:contributor.*
Author dc:creator
  • Albrecht, David R.
Contributors dc:contributor
  • Borisov, Nikita

Subjects

dc:subject × 8

Rights

dc:rights
Statement dc:rights
  • Copyright 2009 David Albrecht.
Language dc:language
en

Identifiers

dc:identifier.*
Handle dc:identifier
http://hdl.handle.net/2142/14658
OAI identifier oai:identifier
oai:www.ideals.illinois.edu:2142/14658

Chain of custody

source
Harvested from
University of Illinois - Urbana-Champaign
Base URL
www.ideals.illinois.edu/oai-pmh
Last updated
2026-07-22
Source record
OAI-PMH GetRecord
citation

Albrecht, David R.. High Performance Network Intrusion Detection: A New Paradigm is Needed. Thesis thesis, University of Illinois at Urbana-Champaign, 2010. http://hdl.handle.net/2142/14658