Performance testing

From: Upo Net (uponet@hotmail.com)
Date: 05/08/02


Date: 8 May 2002 11:43:49 -0000
From: Upo Net <uponet@hotmail.com>
To: focus-ids@securityfocus.com


('binary' encoding is not supported, stored as-is)

Hi,

I've some troubles with NIDS performance testing.
I'm using these devices:
- Linux box: RedHat7.2, Pentium IV 1400MHz
             RAM 384MB, NIC 3Com 905
             Snort 1.8.6

- Linux box: RedHat7.2, Hp e-pc40, Celeron 900
             Nessus

- Linux box: RedHat7.2, Pentium 200
             Apache Web Server

- Smartbits 600, with Smartflow

I'm using Nesuss to send some attacks to the Apache Server,
when I'm generating noise traffic with the Smartbits.

I'm generating this kind of traffic:
100 TCP flows from 192.168.66.9-109 random port to
192.168.66.1 port 80, with these shaping:
- 60% size 76byte (ethernet);
- 15% size 594byte
- 15% size 1518byte
- other sizes;

The problem is that with 10% of load my NIDS melts, running
at 99% of CPU time.

Why? Can someone help me?

Thank you.

- uponet

P.S.
I'm using the standard configuration of Snort, and It's
running with the high speed option enabled:
#snort -i eth1 -c /etc/snort/snort.conf -b -A fast

    



Relevant Pages

  • Re: Linux vs MS Security
    ... This code will lock up any P5 machine, even usermode Linux! ... ] problem doesn't show itself for the Pentium Pro or Pentium 2. ... Nov 1997 16:38:48 -0700 announcing the BSDi fix. ... Pentium bug workaround, please test! ...
    (comp.os.linux)
  • Re: Linux distro request
    ... Linux will run that small, just not with everything and the kitchen ... machines prior to AMD K6-2 500Mhz and Pentium II 450Mhz have been retired, ... cpu for a modern OS without heavy GUI use. ... 486 is approximately half as fast as an equivalent Pentium with the ...
    (alt.lang.asm)
  • Re: Installing FreeBSD on old PC, just for learning
    ... I know this based on Linux experience. ... > If it were a personal friend wanting to explore FreeBSD, ... I don't have this laying around. ... My main machine is a Pentium III computer ...
    (comp.unix.bsd.freebsd.misc)
  • Yet Another Linux Newbie
    ... I'm Yet Another Linux Newbie. ... trade looking to upgrade my skillset and thereby widening my ... employment possibilities. ... Compaq Proliant (dual 200mHz Pentium Pro) ...
    (comp.os.linux.misc)
  • Re: Ultrasparc IIe vs Pentium III
    ... > The pentium would run freebsd with apache, mysql, many chroot jails, ... > or linux with usermode linux jails. ... run Solaris x86 on that Pentium. ... is MySQL a good choice? ...
    (comp.sys.sun.hardware)

Quantcast