首页> 外文会议> >Work in Progress: Bro-LAN Pervasive Network Inspection and Control for LAN Traffic
【24h】

Work in Progress: Bro-LAN Pervasive Network Inspection and Control for LAN Traffic

机译:正在进行的工作:针对局域网流量的Bro-LAN普适网络检查和控制

获取原文
获取外文期刊封面目录资料

摘要

Network intrusion detection and prevention systems (NIDS and NIPS) have to date focused on protecting external access links, or, when internally deployed, links between major enclaves in an enterprise. As previously argued, major threats (worms, insiders, and attackers with a toehold) come from inside the local network, rather than outside. Recently, two approaches have arisen to address this threat: ubiquitous deployment of end system monitors and custom hardware to replace switching infrastructure. This paper presents a third way: exploiting the VLAN capabilities of modern switches to enforce that all LAN communications must traverse and meet the approval of an intrusion detection monitor that operates separately from the switches. This architecture can realize two key benefits: (1) deployment and operation in today''s enterprise networks without requiring replacement of existing network infrastructure, and (2) the use of highly flexible, commodity PCs for LAN monitoring, rather than algorithms embedded in difficult-to-reprogram custom hardware
机译:迄今为止,网络入侵检测和防御系统(NIDS和NIPS)必须专注于保护外部访问链接,或者在内部部署时保护企业中主要飞地之间的链接。如前所述,主要威胁(蠕虫,内部人员和具有一定权柄的攻击者)来自本地网络内部,而不是外部。最近,已经出现了两种方法来应对这一威胁:广泛部署终端系统监视器和定制硬件来替代交换基础架构。本文提出了第三种方法:利用现代交换机的VLAN功能来强制所有LAN通信都必须经过并获得与交换机分开运行的入侵检测监视器的批准。这种体系结构可以实现两个主要优点:(1)在当今的企业网络中进行部署和运行,而无需替换现有的网络基础结构;(2)使用高度灵活的商用PC进行LAN监视,而不是将其嵌入到算法中。难以重新编程的自定义硬件

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号