首页> 外文会议> >Searching for open windows and unlocked doors: port scanning in large-scale commodity clusters
【24h】

Searching for open windows and unlocked doors: port scanning in large-scale commodity clusters

机译:搜索开着的窗户和开着的门:大型商品集群中的端口扫描

获取原文

摘要

Current methods for monitoring the security of large-scale commodity clusters tend to treat these clusters as nothing more than collections of independent nodes. As such, the techniques used to secure these clusters have, for the most part, been adaptations of techniques developed for securing and monitoring enterprise computing environments. We have previously proposed the idea of monitoring the security-state of large-scale commodity clusters by examining their emergent properties, that is, properties that are only visible when one ceases to look at a cluster as a collection of disparate nodes and begins to look at the properties of the cluster as a whole. We show that by correlating the open network ports observed on cluster nodes with other emergent properties - such as active processes and the contents of important system files - security analysts can make insightful observations that can greatly restrict the actions that an attacker can carry out undetected.
机译:当前监视大型商品集群安全性的方法倾向于将这些集群视为独立节点的集合。这样,用于保护这些集群的技术在大多数情况下是对为保护和监视企业计算环境而开发的技术的改编。我们以前曾提出过通过检查大型商品集群的紧急状态来监视大型商品集群的安全状态的想法,即,只有当人们不再将集群视为一组完全不同的节点并开始查看时,这些属性才可见整个集群的属性。我们表明,通过将在群集节点上观察到的开放网络端口与其他紧急属性(例如活动进程和重要系统文件的内容)相关联,安全分析人员可以进行有见地的观察,从而极大地限制了攻击者可以执行的未被发现的动作。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号