Improving intrusion detection and prevention system (IDPS) performance in an IPv6 environment

Sadiq, A. and Bul'ajoul, W. ORCID: 0000-0003-4927-9500, 2020. Improving intrusion detection and prevention system (IDPS) performance in an IPv6 environment. Advances in Networks, 8 (2), pp. 22-33. ISSN 2326-9766

[img]
Preview
Text
1401535_Bul'ajoul.pdf - Published version

Download (1MB) | Preview

Abstract

This paper presents a comprehensive investigation, backed up by detailed simulations, that the default settings of the software based open source Intrusion Detection and Prevention Systems (IDPs) are not enough to thwart the network attacks in a modern high-speed IPv6-only environment. It aims to solve this problem by improving the processing capabilities of an IDPS in more than one way, with each method being totally independent from the other. The proposed solution can be implemented by any user running an IDPS, without needing escalated privileges. Using and IPv6 packet generator, it is shown that with the increase in IPv6 traffic in a fixed amount of time, the IDPS fails to analyse all the packets and starts dropping them. This phenomenon compromises the core functionality of IDPS which is to stop the unwanted traffic. A hybrid solution has been proposed to increase the performance of the IDPS. Our research involves only the system running an IDPS, with little to no tweaking of the other elements within a network like routers, switches and firewalls. The paper also talks briefly about the current and the future generation of the IDPSs. The simulation with the hybrid solution concludes that the performance is improved to a staggering 200%, approximately, compared to the built-in settings of the IDPS.

Item Type: Journal article
Publication Title: Advances in Networks
Creators: Sadiq, A. and Bul'ajoul, W.
Publisher: Science Publishing Group
Date: December 2020
Volume: 8
Number: 2
ISSN: 2326-9766
Identifiers:
NumberType
10.11648/j.net.20200802.12DOI
1401535Other
Rights: Copyright © 2020 Authors retain the copyright of this article. This article is an open access article distributed under the Creative Commons Attribution License (http://creativecommons.org/licenses/by/4.0/) which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.
Divisions: Schools > School of Science and Technology
Record created by: Jeremy Silvester
Date Added: 21 Jan 2021 15:53
Last Modified: 21 Jan 2021 15:53
URI: http://irep.ntu.ac.uk/id/eprint/42076

Actions (login required)

Edit View Edit View

Views

Views per month over past year

Downloads

Downloads per month over past year