...
首页> 外文期刊>Journal of Information Security >Experimental Evaluation of Cisco ASA-5510 Intrusion Prevention System against Denial of Service Attacks
【24h】

Experimental Evaluation of Cisco ASA-5510 Intrusion Prevention System against Denial of Service Attacks

机译:Cisco ASA-5510入侵防御系统针对拒绝服务攻击的实验评估

获取原文
   

获取外文期刊封面封底 >>

       

摘要

Cyber attacks are continuing to hamper working of Internet services despite increase in the use of network security systems such as, firewalls and Intrusion protection systems (IPS). Recent Denial of Service (DoS) attack on Independence Day weekend, on July 4th, 2009 launched to debilitate the US and South Korean governments’ websites is indicative of the fact that the security systems may not have been adequately deployed to counteract such attacks. IPS is a vital security device which is commonly used as a front line defense mechanism to defend against such DoS attacks. Before deploying a firewall or an IPS device for network protection, in many deployments, the performance of firewalls is seldom evaluated for their effectiveness. Many times, these IPS’s can become bottleneck to the network performance and they may not be effective in stopping DoS attacks. In this paper, we intend to drive the point that deploying IPS may not always be effective in stopping harmful effects of DoS attacks. It is important to evaluate the capability of IPS before they are deployed to protect a network or a server against DoS attacks. In this paper, we evaluate performance of a commercial grade IPS Cisco ASA-5510 IPS to measure its effectiveness in stopping a DoS attacks namely TCP-SYN, UDP Flood, Ping Flood and ICMP Land Attacks. This IPS comes with features to counteract and provide security against these attacks. Performance of the IPS is measured under these attacks protection and compared with its performance when these protection features were not available (i.e. disabled). It was found that the IPS was unable to provide satisfactory protection despite the availability of the protection features against these flooding attacks. It is important for the network managers to measure the actual capabilities of an IPS system before its deployment to protect critical information infrastructure.
机译:尽管增加了对网络安全系统(如防火墙和入侵防护系统(IPS))的使用,但网络攻击仍在继续阻碍Internet服务的运行。 2009年7月4日独立日周末发生的最近的拒绝服务(DoS)攻击使美国和韩国政府的网站瘫痪,这表明事实表明,可能尚未充分部署安全系统来抵抗此类攻击。 IPS是至关重要的安全设备,通常用作防御此类DoS攻击的前线防御机制。在部署防火墙或IPS设备进行网络保护之前,在许多部署中,很少评估防火墙性能的有效性。很多时候,这些IPS可能成为网络性能的瓶颈,并且可能无法有效地阻止DoS攻击。在本文中,我们打算指出以下观点:部署IPS可能并不总是能够有效地阻止DoS攻击的有害影响。在部署IPS之前,请评估IPS的能力,以保护网络或服务器免受DoS攻击,这一点很重要。在本文中,我们评估了商业级IPS Cisco ASA-5510 IPS的性能,以衡量其在阻止DoS攻击(即TCP-SYN,UDP Flood,Ping Flood和ICMP Land攻击)中的有效性。该IPS具有抵消和提供针对这些攻击的安全性的功能。 IPS的性能是根据这些攻击防护来衡量的,并与这些防护功能不可用(即禁用)时的性能进行比较。发现尽管提供了针对这些洪泛攻击的保护功能,但IPS无法提供令人满意的保护。对于网络管理员而言,在部署IPS系统之前测量其实际功能非常重要,以保护关键的信息基础架构。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号