RISS 학술연구정보서비스

검색

인기 검색어

    다국어 입력

    http://chineseinput.net/에서 pinyin(병음)방식으로 중국어를 변환할 수 있습니다.

    변환된 중국어를 복사하여 사용하시면 됩니다.

    예시)
    • 中文 을 입력하시려면 zhongwen을 입력하시고 space를누르시면됩니다.
    • 北京 을 입력하시려면 beijing을 입력하시고 space를 누르시면 됩니다.
    닫기
    KCI등재

    MongoDB 기반의 분산 침입탐지시스템 성능 평가 = Evaluation of Distributed Intrusion Detection System Based on MongoDB

    한글로보기

    https://www.riss.kr/link?id=A106489227

    • 0

      상세조회
    • 0

      다운로드
    서지정보 열기
    • 내보내기
    • 내책장담기
    • 공유하기
    • 오류접수

    부가정보

    다국어 초록 (Multilingual Abstract) kakao i 다국어 번역

    Due to the development and increased usage of Internet services such as IoT and cloud computing, a large number of packets are being generated on the Internet. In order to create a safe Internet environment, malicious data that may exist among these packets must be processed and detected quickly. In this paper, we apply MongoDB, which is specialized for unstructured data analysis and big data processing, to intrusion detection system for rapid processing of big data security events. In addition, building the intrusion detection system(IDS) using some of the private cloud resources which is the target of protection, elastic and dynamic reconfiguration of the IDS is made possible as the number of security events increase or decrease. In order to evaluate the performance of MongoDB – based IDS proposed in this paper, we constructed prototype systems of IDS based on MongoDB as well as existing relational database, and compared their performance. Moreover, the number of virtual machine has been increased to find out the performance change as the IDS is distributed. As a result, it is shown that the performance is improved as the number of virtual machine is increased to make IDS distributed in MongoDB environment but keeping the overall system performance unchanged. The security event input rate based on distributed MongoDB was faster as much as 60%, and distributed MongoDB-based intrusion detection rate was faster up to 100% comparing to the IDS based on relational database.
    번역하기

    Due to the development and increased usage of Internet services such as IoT and cloud computing, a large number of packets are being generated on the Internet. In order to create a safe Internet environment, malicious data that may exist among these p...

    Due to the development and increased usage of Internet services such as IoT and cloud computing, a large number of packets are being generated on the Internet. In order to create a safe Internet environment, malicious data that may exist among these packets must be processed and detected quickly. In this paper, we apply MongoDB, which is specialized for unstructured data analysis and big data processing, to intrusion detection system for rapid processing of big data security events. In addition, building the intrusion detection system(IDS) using some of the private cloud resources which is the target of protection, elastic and dynamic reconfiguration of the IDS is made possible as the number of security events increase or decrease. In order to evaluate the performance of MongoDB – based IDS proposed in this paper, we constructed prototype systems of IDS based on MongoDB as well as existing relational database, and compared their performance. Moreover, the number of virtual machine has been increased to find out the performance change as the IDS is distributed. As a result, it is shown that the performance is improved as the number of virtual machine is increased to make IDS distributed in MongoDB environment but keeping the overall system performance unchanged. The security event input rate based on distributed MongoDB was faster as much as 60%, and distributed MongoDB-based intrusion detection rate was faster up to 100% comparing to the IDS based on relational database.

    더보기

    국문 초록 (Abstract) kakao i 다국어 번역

    IoT, 클라우드 컴퓨팅과 같은 인터넷 서비스의 발전과 사용량의 증가로 인해 수많은 패킷들이 인터넷상에서 빠르게 생성되고 있다. 안전한 인터넷 사용 환경을 만들기 위해서는 이 수많은 패킷 중에 존재할 수 있는 악성 데이터의 빠른 처리가 이뤄져야 한다. 본 논문에서는 빅데이터 보안 이벤트의 신속한 처리를 위해 비정형 데이터 분석과 빅데이터 처리에 특화된 MongoDB를 침입탐지시스템에 적용하였다. 또한 보호 대상인 사설 클라우드의 일부 자원을 이용하여 침입탐지시스템을 구축함으로써 증가 또는 감소하는 보안 이벤트 수에 따라 탄력적으로 컴퓨팅 자원 재구성이 가능하도록 하였다. 본 논문에서 제안하는 MongoDB 기반 침입탐지시스템의 성능을 평가하기 위하여 MongoDB 기반의 침입탐지시스템과 기존의 관계형 데이터베이스를 기반으로 한 침입탐지시스템의 프로토타입을 구축하고 성능을 비교하였다. 또한 분산화 구성에 따른 성능 변화를 확인하기 위하여 가상머신의 수를 변경하며 성능 변화를 확인하였다. 그 결과 전체적으로 MongoDB 환경에서 동일한 성능의 시스템을 분산화시켜 가상 머신의 수를 증가시킬수록 침입탐지시스템의 성능이 향상되는 것을 확인하였다. 분산 MongoDB 기반의 보안 이벤트 저장 속도가 관계형 데이터베이스 기반에 비해 최대 60%, 그리고 분산 MongoDB 기반의 침입 데이터 탐지 속도가 관계형 데이터베이스 기반에 비해 최대 100% 빠른 결과를 얻었다.
    번역하기

    IoT, 클라우드 컴퓨팅과 같은 인터넷 서비스의 발전과 사용량의 증가로 인해 수많은 패킷들이 인터넷상에서 빠르게 생성되고 있다. 안전한 인터넷 사용 환경을 만들기 위해서는 이 수많은 패...

    IoT, 클라우드 컴퓨팅과 같은 인터넷 서비스의 발전과 사용량의 증가로 인해 수많은 패킷들이 인터넷상에서 빠르게 생성되고 있다. 안전한 인터넷 사용 환경을 만들기 위해서는 이 수많은 패킷 중에 존재할 수 있는 악성 데이터의 빠른 처리가 이뤄져야 한다. 본 논문에서는 빅데이터 보안 이벤트의 신속한 처리를 위해 비정형 데이터 분석과 빅데이터 처리에 특화된 MongoDB를 침입탐지시스템에 적용하였다. 또한 보호 대상인 사설 클라우드의 일부 자원을 이용하여 침입탐지시스템을 구축함으로써 증가 또는 감소하는 보안 이벤트 수에 따라 탄력적으로 컴퓨팅 자원 재구성이 가능하도록 하였다. 본 논문에서 제안하는 MongoDB 기반 침입탐지시스템의 성능을 평가하기 위하여 MongoDB 기반의 침입탐지시스템과 기존의 관계형 데이터베이스를 기반으로 한 침입탐지시스템의 프로토타입을 구축하고 성능을 비교하였다. 또한 분산화 구성에 따른 성능 변화를 확인하기 위하여 가상머신의 수를 변경하며 성능 변화를 확인하였다. 그 결과 전체적으로 MongoDB 환경에서 동일한 성능의 시스템을 분산화시켜 가상 머신의 수를 증가시킬수록 침입탐지시스템의 성능이 향상되는 것을 확인하였다. 분산 MongoDB 기반의 보안 이벤트 저장 속도가 관계형 데이터베이스 기반에 비해 최대 60%, 그리고 분산 MongoDB 기반의 침입 데이터 탐지 속도가 관계형 데이터베이스 기반에 비해 최대 100% 빠른 결과를 얻었다.

    더보기

    참고문헌 (Reference)

    1 Ali Shiravi, "Toward Developing a Systematic Approach to Generate Benchmark Datasets for Intrusion Detection" 31 (31): 357-374, 2012

    2 J. Beale, "Snort : IDS and IPS Toolkit" Syngress 2007

    3 ATEZENI, "Relational Database Theory" Addison Wesley Longman 1993

    4 "OpenStack"

    5 H. J. Han, "NoSQL-Based Distributed Processing System for Processing BigData Security Event" Korea Information Processing Society 24 (24): 2017

    6 Shannon Bradshaw, "Mongodb : The Definitive Guide :Powerful and Scalable Data Storage" O’ReillyMedia 2017

    7 "MongoDB"

    8 "MariaDB Spider Storage Engine"

    9 "MariaDB"

    10 "IoT 2020 : Smart and Secure IoT Platform" International Electrotechnical Commission 1-181, 2016

    1 Ali Shiravi, "Toward Developing a Systematic Approach to Generate Benchmark Datasets for Intrusion Detection" 31 (31): 357-374, 2012

    2 J. Beale, "Snort : IDS and IPS Toolkit" Syngress 2007

    3 ATEZENI, "Relational Database Theory" Addison Wesley Longman 1993

    4 "OpenStack"

    5 H. J. Han, "NoSQL-Based Distributed Processing System for Processing BigData Security Event" Korea Information Processing Society 24 (24): 2017

    6 Shannon Bradshaw, "Mongodb : The Definitive Guide :Powerful and Scalable Data Storage" O’ReillyMedia 2017

    7 "MongoDB"

    8 "MariaDB Spider Storage Engine"

    9 "MariaDB"

    10 "IoT 2020 : Smart and Secure IoT Platform" International Electrotechnical Commission 1-181, 2016

    11 Rehman, "Intrusion Detection Systems With Snort: Advance IDS Techniques Using Snort, Apache, MySQL, PHP, and ACID" Prentice Hall 2003

    12 G. Serpen, "Host-based Misuse Intrusion Detection using PCA Feature Extraction and kNN Classification Algorithms" 22 (22): 1101-1114, 2018

    13 M. H. Kang, "Completion of IDS and Security Control by Big Data Analysis" Wowbooks 2013

    14 G. Lu, "Cloud Computing Survey" 530-531 : 650-661, 2014

    15 M. Chen, "Big Data : A Survey" 19 (19): 171-209, 2014

    16 S. Aljawarneh, "Anomalybased Intrusion Detection System Through Feature Selection Analysis and Building Hybrid Efficient Model" 25 : 152-160, 2018

    17 Y. W. Kim, "Analysis and Understanding of Cloud Computing" The Korean Institute of Communication and Information Sciences 87-92, 2015

    18 M. Armbrust, "Above the Clouds : A Berkeley View of Cloud Computing"

    더보기

    분석정보

    View

    상세정보조회

    0

    Usage

    원문다운로드

    0

    대출신청

    0

    복사신청

    0

    EDDS신청

    0

    동일 주제 내 활용도 TOP

    더보기

    주제

    연도별 연구동향

    연도별 활용동향

    연관논문

    연구자 네트워크맵

    공동연구자 (7)

    유사연구자 (20) 활용도상위20명

    인용정보 인용지수 설명보기

    학술지 이력

    학술지 이력
    연월일 이력구분 이력상세 등재구분
    2027 평가 재인증평가 신청대상 (재인증)
    2021-01-01 등재 등재학술지 유지 (재인증) KCI등재
    2018-01-01 등재 등재학술지 유지 (등재유지) KCI등재
    2015-01-01 등재 등재학술지 유지 (등재유지) KCI등재
    2012-10-31 학술지명변경 한글명 : 컴퓨터 및 통신시스템 -> 정보처리학회논문지. 컴퓨터 및 통신시스템 KCI등재
    2012-10-10 학술지명변경 한글명 : 정보처리학회논문지A -> 컴퓨터 및 통신시스템
    외국어명 : The KIPS Transactions Part : A -> KIPS Transactions on Computer and Communication Systems
    KCI등재
    2010-01-01 등재 등재학술지 유지 (등재유지) KCI등재
    2009-03-04 학술지명변경 한글명 : 정보처리학회논문지 A, B, C, D -> 정보처리학회논문지 A
    외국어명 : The KIPS Transactions Part : A, B, C, D -> The KIPS Transactions Part : A
    KCI등재
    2009-03-04 학술지명변경 한글명 : 정보처리학회논문지 A -> 정보처리학회논문지A KCI등재
    2008-01-01 등재 등재학술지 유지 (등재유지) KCI등재
    2006-01-01 등재 등재학술지 유지 (등재유지) KCI등재
    2003-01-01 등재 등재학술지 선정 (등재후보2차) KCI등재
    2002-01-01 등재 등재후보 1차 PASS (등재후보1차) KCI등재후보
    2000-07-01 등재 등재후보학술지 선정 (신규평가) KCI등재후보
    더보기

    학술지 인용정보

    학술지 인용정보
    기준연도 WOS-KCI 통합IF(2년) KCIF(2년) KCIF(3년)
    2016 0.16 0.16 0.14
    KCIF(4년) KCIF(5년) 중심성지수(3년) 즉시성지수
    0.12 0.11 0.315 0.07
    더보기

    이 자료와 함께 이용한 RISS 자료

    나만을 위한 추천자료

    해외이동버튼