Improving the Accuracy of Network Intrusion Detection Systems Under Load Using Selective Packet Discarding
Under conditions of heavy traffic load or sudden traffic bursts, the peak processing throughput of Network Intrusion Detection Systems (NIDS) may not be sufficient for inspecting all monitored traffic, and the packet capturing subsystem inevitably drops excess arriving packets before delivering them to the NIDS. This impedes the detection ability of the system and leads to missed attacks. In this paper, the authors present selective packet discarding, a best effort approach that enables the NIDS to anticipate overload conditions and minimize their impact on attack detection. Instead of letting the packet capturing subsystem randomly drop arriving packets, the NIDS proactively discards packets that are less likely to affect its detection accuracy, and focuses on the traffic at the early stages of each network flow.