首页> 外文会议>International Conference on Network and System Security >Luth: Composing and Parallelizing Midpoint Inspection Devices
【24h】

Luth: Composing and Parallelizing Midpoint Inspection Devices

机译:Luth:组成和并行化中点检测装置

获取原文

摘要

The race for innovation is driving Internet evolution. Internet software developers have to create more complex systems while enduring the pressuring time to market. Therefore, end-host software have bugs, vulnerabilities and cannot be trusted. That's why, among others, network Intrusion Detection System (IDS), Intrusion Prevention System (IPS), firewall or other network devices monitor such software to prevent unexpected behaviors. However, their functionalities are limited by design, because they can only handle a configuration of predefined monolithic protocol layerings. In this paper we present Luth, a midpoint inspection device that relies on the composition and parallelization of predefined midpoint inspectors (MI). We present the main functionalities offered by its configuration language and interpreter. Finally, we benchmark a prototype implemented in OCaml. This prototype runs in the user space of a GNU/Linux operating system, by means of the libnet filter_queue library. We show how it efficiently inspects and filters DNS hidden-channels encapsulated into 20 GRE tunnels.
机译:创新种族正在推动互联网演变。互联网软件开发人员必须创建更复杂的系统,同时持续向市场压力。因此,最终主机软件具有错误,漏洞,无法信任。这就是为什么,包括网络入侵检测系统(IDS),入侵防御系统(IPS),防火墙或其他网络设备监视这种软件以防止意外行为。然而,它们的功能受设计的限制,因为它们只能处理预定义的单片协议分层的配置。在本文中,我们提出了一种依赖于预定义的中点检查员(MI)的组成和并行化的中点检查装置。我们介绍了其配置语言和翻译提供的主要功能。最后,我们基准在OCAML中实现的原型。此原型通过libnet filter_queue库在GNU / Linux操作系统的用户空间中运行。我们展示了如何有效检查和过滤封装成20个GRE隧道的DNS隐藏通道。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号