首页> 外文会议>International conference on ICT systems security and privacy protection >Zeek-Osquery: Host-Network Correlation for Advanced Monitoring and Intrusion Detection
【24h】

Zeek-Osquery: Host-Network Correlation for Advanced Monitoring and Intrusion Detection

机译:Zeek-Osquery:高级监控和入侵检测的主机网络相关性

获取原文

摘要

Intrusion Detection Systems (IDSs) can analyze network traffic for signs of attacks and intrusions. However, encrypted communication limits their visibility and sophisticated attackers additionally try to evade their detection. To overcome these limitations, we extend the scope of Network IDSs (NIDSs) with additional data from the hosts. For that, we propose the integrated open-source zeek-osquery platform that combines the Zeek IDS with the osquery host monitor. Our platform can collect, process, and correlate host and network data at large scale, e.g., to attribute network flows to processes and users. The platform can be flexibly extended with own detection scripts using already correlated, but also additional and dynamically retrieved host data. A distributed deployment enables it to scale with an arbitrary number of osquery hosts. Our evaluation results indicate that a single Zeek instance can manage more than 870 osquery hosts and can attribute more than 96% of TCP connections to host-side applications and users in real-time.
机译:入侵检测系统(IDS)可以分析网络流量的攻击和入侵的迹象。但是,加密通信限制了他们的可见性和复杂的攻击者,另外尝试逃避他们的检测。为了克服这些限制,我们将网络IDS(nidss)的范围扩展到主机的附加数据。为此,我们提出了集成的开源Zeek-OsQuery平台,将Zeek ID与OsQuery主机监视器相结合。我们的平台可以在大规模的大规模中收集,处理和关联主机和网络数据,例如,将网络流到进程和用户。使用已关联的自身检测脚本可以灵活地扩展平台,但还可以额外的和动态检索的主数据。分布式部署使其能够使用任意数量的OsQuery主机进行缩放。我们的评估结果表明,单个Zeek实例可以管理超过870个OsQuery主机,并且可以将超过96%的TCP连接与主机端应用程序和用户实时地属于主机端应用程序和用户。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号