首页> 外文会议>International symposium on research in attacks, intrusions and defenses >Providing Dynamic Control to Passive Network Security Monitoring
【24h】

Providing Dynamic Control to Passive Network Security Monitoring

机译:为被动网络安全监控提​​供动态控制

获取原文

摘要

Passive network intrusion detection systems detect a wide range of attacks, yet by themselves lack the capability to actively respond to what they find. Some sites thus provide their IDS with a separate control channel back to the network, typically by enabling it to dynamically insert ACLs into a gateway router for blocking IP addresses. Such setups, however, tend to remain narrowly tailored to the site's specifics, with little opportunity for reuse elsewhere, as different networks deploy a wide array of hard- and software and differ in their network topologies. To overcome the shortcomings of such ad-hoc approaches, we present a novel network control framework that provides passive network monitoring systems with a flexible, unified interface for active response, hiding the complexity of heterogeneous network equipment behind a simple task-oriented API. Targeting operational deployment in large-scale network environments, we implement the design of our framework on top of an existing open-source IDS. We provide exemplary backends, including an interface to OpenFlow hardware, and evaluate our approach in terms of functionality and performance.
机译:被动网络入侵检测系统可以检测到各种各样的攻击,但是它们自身缺乏主动响应所发现内容的能力。因此,某些站点通常通过使其能够将ACL动态插入ACL到网关路由器中来阻止IP地址,从而为其IDS提供返回网络的单独控制通道。但是,由于不同的网络部署了各种各样的硬件和软件,并且它们的网络拓扑结构也有所不同,因此此类设置倾向于严格地针对站点的具体情况进行调整,几乎没有在其他地方重用的机会。为了克服此类临时方法的缺点,我们提出了一种新颖的网络控制框架,该框架为被动网络监视系统提供了灵活,统一的界面来进行主动响应,从而将异构网络设备的复杂性隐藏在了简单的面向任务的API之后。针对大型网络环境中的运营部署,我们在现有开源IDS的基础上实施我们框架的设计。我们提供了示例性的后端,包括与OpenFlow硬件的接口,并在功能和性能方面评估了我们的方法。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号