Feasibility of eliminating IDPS devices from a web server farm
journal contribution
posted on 2024-11-03, 15:36authored bySujatha Sivabalan, Peter Radcliffe
Current web security systems need Intrusion Detection and Prevention Systems (IDPS), web proxies and rewalls to protect the websites from malicious network trac. All these functions come at a cost for a web farm and add to power costs. Our previous work has concluded that the web server detection of application layer DDoS attacks is far more power ecient than an equivalent IDPS. This paper shows that all remaining IDPS functionality can be split between the rewall and the web server allowing the removal of the traditional IDPS and so substantially reducing the CPU load and total electrical power bill of a web farm.