【24h】

An SNMP agent for stateful intrusion inspection

机译:用于状态入侵检查的SNMP代理

获取原文

摘要

Intrusion detection systems (IDS) have been increasingly used in organizations, in addition to other security mechanisms, to detect intrusions to systems and networks. In the recent years several IDS have been released, but (a) the high number of false alarms generated, (b) the lack of a high-level notation for attack signature specification, and (c) the difficulty to integrate IDS with existing network management infrastructure hinder their widespread and efficient use. In this paper we address these problems by presenting an SNMP agent for stateful intrusion inspection. By using a state machine-based language called PTSL (Protocol Trace Specification Language), the network manager can describe attack signatures that should be monitored. The signatures to be used by the agent are configured by the network manager through the IETF Script MIB. Once programmed, the agent starts monitoring the occurrence of the signatures on the network traffic and stores statistics, according to their occurrence, in an extended RMON2 MIB. These statistics may be retrieved from any SNMP-based management application and can be used to accomplish signature-based analysis. The paper also describes two experiments that have been carried out with the agent to assess its performance and to demonstrate its effectiveness in terms of false alarm generation rates.
机译:除其他安全机制外,入侵检测系统(IDS)已在组织中越来越多地用于检测对系统和网络的入侵。近年来,已经发布了一些IDS,但是(a)产生了大量的虚假警报,(b)缺乏针对攻击签名规范的高级注释,以及(c)难以将IDS与现有网络集成管理基础架构阻碍了它们的广泛和有效使用。在本文中,我们通过提供用于状态入侵检查的SNMP代理来解决这些问题。通过使用称为PTSL(协议跟踪规范语言)的基于状态机的语言,网络管理器可以描述应监视的攻击特征。网络管理器通过IETF脚本MIB配置代理要使用的签名。进行编程后,代理将开始监视网络流量上的签名的发生,并根据它们的出现将统计信息存储在扩展的RMON2 MIB中。这些统计信息可以从任何基于SNMP的管理应用程序中检索到,并可用于完成基于签名的分析。本文还描述了与代理一起执行的两个实验,以评估其性能并根据错误警报的发生率证明其有效性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号