Intrusion Detection at 100G

SESSION: State of the Practice - AICS/Security/Net

EVENT TYPE: State of the Practice

TIME: 2:00PM - 2:30PM


AUTHOR(S):Scott Campbell, Jason Lee


Driven by the growing data transfer needs of the scientific community and the finalization of the 100 Gbps Ethernet Specification, 100 Gbps will soon become a reality for many HPC sites. This tenfold increase in bandwidth creates a number of significant technical challenges. We show that by using the heavy tail flow effect as a filter, it should be possible to perform active IDS analysis at this traffic rate using a cluster of commodity systems driven by a dedicated load balancing mechanism. Additionally, we examine and characterize current traffic behavior, and apply it to scaling infrastructure at 100Gbps.

Chair/Author Details:

David Martin (Chair) - Argonne National Lab

Scott Campbell - Lawrence Berkeley National Laboratory

Jason Lee - Lawrence Berkeley National Laboratory

