负载均衡是基于多核平台实现高速入侵检测系统的关键技术之一。基于真实流量统计分析发现的流阈值与流数目、流字节数之间变化的规律,提出只调整较大流的动态分流算法HCLF,并实现了原型系统。实验测试表明,与静态哈希算法和新流调整算法相比,HCLF算法在负载均衡度、系统丢包率方面具有显著的优越性,改善了多核平台高速入侵检测系统对突发流量和应用环境的适应性。
Load balancing is one of the key technologies of designing high-speed intrusion detection system(IDS) based on multi-core platform.In terms of statistic analysis to the real Internet traffic,this paper found the law about the threshold of flows,the number of flows and the number of their bytes.It proposed a novel load balancing algorithm(named HCLF),which adjusted only the large flows.After the antitype system was implemented,the experiments show that HCLF has the distinct advantage on load balancing metric and packet loss rate,compare with the static hash algorithm and the adjusting new flow algorithm.It improves the adaptability of the high-speed IDS based on multi-core platform to sudden load and environment.