Title: Running an IDS Virtual Network Function inside an SDN Bare Metal Commodity Switch
Authors: Wang, Shie-Yuan
Hsieh, Yi-Hsuan
資訊工程學系
Department of Computer Science
Keywords: SDN;bare metal commodity switch;intrusion detection system;network function virtualization
Issue Date: 1-Jan-2018
Abstract: In this paper, we design, implement, and evaluate the real performance of running multiple Snort IDS (intrusion detection system) VNFs (virtual network function) inside a bare metal commodity switch. In the past, normally people ran Snort on a stand-alone server and configure switches to direct packets to it for inspection. However, more recently there is a trend to implement and run VNF directly inside a switch for immediate and intelligent processing of packets. Our work of running Snort directly inside a bare metal commodity switch as a VNF is the first work of its kind in the world. In this paper, we present real performance results and important findings from this innovative work.
URI: http://hdl.handle.net/11536/153996
ISBN: 978-1-5386-3180-5
ISSN: 1550-3607
Journal: 2018 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC)
Begin Page: 0
End Page: 0
Appears in Collections:Conferences Paper