首页> 外文会议> >A network audit system for host-based intrusion detection (NASHID) in Linux
【24h】

A network audit system for host-based intrusion detection (NASHID) in Linux

机译:Linux中用于基于主机的入侵检测(NASHID)的网络审核系统

获取原文

摘要

Recent work has shown that conventional operating system audit trails are insufficient to detect low-level network attacks. Because audit trails are typically based upon system calls or application sources, operations in the network protocol stack go unaudited. Earlier work has determined the audit data needed to detect low-level network attacks. We describe an implementation of an audit system which collects this data and analyze the issues that guided the implementation. Finally, we report the performance impact on the system and the rate of audit data accumulation in a test network.
机译:最近的工作表明,常规的操作系统审核记录不足以检测低级网络攻击。因为审核跟踪通常基于系统调用或应用程序源,所以网络协议堆栈中的操作将未经审核。早期的工作已经确定了检测低级网络攻击所需的审核数据。我们描述了一个审计系统的实施,该系统收集了这些数据并分析了指导实施的问题。最后,我们报告了性能对系统的影响以及测试网络中审核数据积累的速度。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号