【24h】

Process Query Systems for Network Security Monitoring

机译:用于网络安全监视的过程查询系统

获取原文
获取原文并翻译 | 示例

摘要

In this paper we present the architecture of our network security monitoring infrastructure based on a Process Query System (PQS). PQS offers a new and powerful way of efficiently processing data streams, based on process descriptions that are submitted as queries. In this case the data streams are familiar network sensors, such as Snort, Netfilter, and Tripwire. The process queries describe the dynamics of network attacks and failures, such as worms, multistage attacks, and router failures. Using PQS the task of monitoring enterprise class networks is simplified, offering a priority-based GUI to the security administrator that clearly outlines events that require immediate attention. The PQS-Net system is deployed on an unsecured production network; the system has successfully detected many diverse attacks and failures.
机译:在本文中,我们介绍了基于过程查询系统(PQS)的网络安全监视基础结构的体系结构。 PQS基于作为查询提交的流程描述,提供了一种有效处理数据流的新颖而强大的方法。在这种情况下,数据流是熟悉的网络传感器,例如Snort,Netfilter和Tripwire。进程查询描述了网络攻击和故障(例如蠕虫,多阶段攻击和路由器故障)的动态。使用PQS简化了监视企业级网络的任务,为安全管理员提供了基于优先级的GUI,该GUI清楚地概述了需要立即引起注意的事件。 PQS-Net系统部署在不安全的生产网络上;该系统已成功检测到许多不同的攻击和故障。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号