首页> 外文期刊>Computer Networks >Bro: a system for detecting network intruders in real-time
【24h】

Bro: a system for detecting network intruders in real-time

机译:兄弟:实时检测网络入侵者的系统

获取原文
获取原文并翻译 | 示例
       

摘要

We describe Bro, a stand-alone system for detecting network intruders in real-time by passively monitoring a network link over which the intruder's traffic transits. We give an overview of the system's design, which emphasizes high-speed (FDDI-rate) monitoring, real-time notification, clear separation between mechanism and policy, and ex- tensibility. To achieve these ends, Bro is divided into an ‘event engine' that reduces a kernel-filtered network traffic stream into a series of higher-level events, and a ‘policy script interpreter' that interprets event handlers written in a specialized language used to express a site's security policy. Event handlers can update state information, synthesize new events, record information to disk, and generate real-time notifications via syslog. We also discuss a number of attacks that attempt to subvert passive monitoring systems and defenses against these, and give particulars of how Bro analyzes the six applications integrated into it so far f Finger, FTP, Portmapper, Ident, Telnet and Rlogin. The system is publicly available in source code form.
机译:我们介绍了Bro,这是一个用于通过被动监视入侵者流量经过的网络链接来实时检测网络入侵者的独立系统。我们对系统的设计进行了概述,其中强调了高速(FDDI速率)监视,实时通知,机制与策略之间的清晰区分以及可扩展性。为了实现这些目标,Bro分为“事件引擎”和“策略脚本解释器”,该“事件引擎”将经过内核过滤的网络流量减少为一系列更高级别的事件,该“策略脚本解释器”解释以特殊语言编写的事件处理程序,表示网站的安全政策。事件处理程序可以更新状态信息,合成新事件,将信息记录到磁盘并通过syslog生成实时通知。我们还将讨论许多旨在破坏被动监控系统的攻击以及针对这些攻击的防御措施,并详细说明Bro如何分析到目前为止集成到其中的六个应用程序f Finger,FTP,Portmapper,Ident,Telnet和Rlogin。该系统以源代码形式公开可用。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号