首页> 外文会议>Annual IEEE/IFIP International Conference on Dependable Systems and Networks Workshops >An Intrusion-Tolerant Firewall Design for Protecting SIEM Systems
【24h】

An Intrusion-Tolerant Firewall Design for Protecting SIEM Systems

机译:一种用于保护SIEM系统的入侵防火墙设计

获取原文

摘要

Nowadays, organizations are resorting to Security Information and Event Management (SIEM) systems to monitor and manage their network infrastructures. SIEMs employ a data collection capability based on many sensors placed in critical points of the network, which forwards events to a core facility for processing and support different forms of analysis (e.g., report attacks in near real time, inventory management, risk assessment). In this paper, we will focus on the defense of the core facility components by presenting a new firewall design that is resilient to very harsh failure scenarios. In particular, it tolerates not only external attacks but also the intrusion of some of its components. The firewall employs a two level filtering scheme to increase performance and to allow for some flexibility on the selection of fault-tolerance mechanisms. The first filtering stage efficiently eliminates the most common forms of attacks, while the second stage supports application rules for a more sophisticated analysis of the traffic. The fault tolerance mechanisms are based on a detection and recovery approach for the first stage, while the second stage uses state machine replication and voting.
机译:如今,组织正在诉诸安全信息和事件管理(SIEM)系统来监控和管理其网络基础架构。 SIEMS基于置于网络的关键点的许多传感器采用数据收集能力,该传感器将事件转发给核心设施进行处理和支持不同形式的分析(例如,近实时报告攻击,库存管理,风险评估)。在本文中,我们将专注于通过呈现一个新的防火墙设计来辩护核心设施组件,这些设计是非常严厉的失败情景。特别是,它不仅容忍外部攻击,也容忍其一些组件的侵入。防火墙采用两个级别的过滤方案来提高性能,并允许在选择容错机制方面进行一些灵活性。第一滤波阶段有效地消除了最常见的攻击形式,而第二阶段支持用于更复杂的流量分析的应用规则。容错机制基于第一阶段的检测和恢复方法,而第二阶段使用状态机复制和投票。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号