Performance Security Trade-off of Network Intrusion Detection and Prevention Systems

dc.contributor.authorMunir, Rashid
dc.contributor.authorAhmed, Botan
dc.contributor.authorAl-Mohannadi, Hamad
dc.contributor.authorMufti, M. Rafiq
dc.contributor.authorNamanya, Anitta Patience
dc.contributor.authorAwan, Irfan
dc.date.accessioned2023-05-05T17:39:08Z
dc.date.available2023-05-05T17:39:08Z
dc.date.issued2016
dc.description.abstractSecurity cyber threats are increasing with most companies being overwhelm by the complexity attached to prevention against attacks. Network Intrusion detection and prevention systems (NIDPS) are now a stable in any enterprise network with the purpose of filtering through the network traffic and sniffing for malicious traffic. Given the amount of traffic generated on enterprise networks nowadays, any NIDPS is sure to go through a big number of packets that a need arises for a performance- security trade-off. On any given day, based on the rules used in the NIDPS, the number of alerts it generates are in thousands. This can be quite overwhelming to security analysts who analyse them to understand the cyber threat landscape. Although it is true the more alerts, the higher the probability of detecting malicious traffic, it is also true that alerts require the traffic to go through many rules which can be quite a performance hindrance. This is the paradox plagued by the cyber security community currently. In this paper, we examine 2 scenarios to evaluate the performance security trade-off for the purpose of propose ways of improving the performance while minimising the impact on the security purpose for the NIDPS.en_US
dc.identifier.citationMunir, R., Ahmed, B., Al-Mohannadi, H., Mufti, M. R., Namanya, A. P., & Awan, I. Performance security trade-off of network intrusion detection and prevention systems. In 32nd UK Performance Engineering Workshop and Cyber Security Workshop (UKPEW/CyberSecW) (pp. 8-9).en_US
dc.identifier.urihttps://www.researchgate.net/profile/Anitta-Patience-Namanya/publication/312630470_Performance_Security_Trade-off_of_Network_Intrusion_Detection_and_Prevention_Systems/links/58dfdf56aca272059aae41e9/Performance-Security-Trade-off-of-Network-Intrusion-Detection-and-Prevention-Systems.pdf
dc.identifier.urihttps://nru.uncst.go.ug/handle/123456789/8638
dc.language.isoenen_US
dc.publisherUK Performance Engineering Workshop and Cyber Security Workshopen_US
dc.subjectNetwork securityen_US
dc.subjectRisk assessmenten_US
dc.subjectNetwork intrusion detection systemen_US
dc.subjectRisk assessmenten_US
dc.subjectPerformance evaluationen_US
dc.titlePerformance Security Trade-off of Network Intrusion Detection and Prevention Systemsen_US
dc.typeArticleen_US
Files
Original bundle
Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
Performance Security Trade-off of.pdf
Size:
1.14 MB
Format:
Adobe Portable Document Format
Description:
Article
License bundle
Now showing 1 - 1 of 1
No Thumbnail Available
Name:
license.txt
Size:
1.71 KB
Format:
Item-specific license agreed upon to submission
Description: