Design and implementation of a distributed early warning system combined with intrusion detection system and honeypot

Design and implementation of a distributed early warning system combined with intrusion detection system and honeypot
复制标题

入侵检测系统与蜜罐相结合的分布式预警系统的设计与实现

DOI:
--
复制
发表时间:
2009
期刊:
International Conference on Hybrid Information Technology
影响因子:
--
通讯作者:
Tae
Tae
中科院分区:
--
文献类型:
--
作者:
Pei;Chung;Tae

文献摘要

被引文献

相似文献

网络攻击与防御是一场永无止境的战争。沿着互联网的快速发展,网络攻击也日益增多和多样化。使用传统的防火墙和入侵检测技术无法与这种快速变化相匹配。针对这一趋势,我们设计并实现了一个分布式预警系统,其中多个客户端收集了广泛的网络攻击活动,如恶意代码,发送攻击活动回到一个中央服务器,并提供警告消息给网络管理员。该系统由Snort入侵检测系统和Nepenthes/Sebek蜜罐软件组成。这种组合伴随着客户端和服务器架构,以便提供具有分析能力的面向攻击的记录的各个方面。当整个监控网络受到攻击时,网络管理员将收到警告通知。为了减轻分布式预警系统的部署负担,我们还将系统实现在live USB上,并且我们的系统可以很容易地安装,具有高度的可移植性和即插即用特性。
Network attack and defense is a never-ending war. Along with the rapid development of the Internet, network attacks have increased and diversified. Use of traditional firewall and intrusion detection technologies cannot match to this rapid change. In response to this trend, we designed and implemented a distributed early warning system where several clients collected a wide range of network attack activities, such as malicious codes, sent attack activities back to a central server, and provided warning messages to the network administrator. The proposed system consists of Snort intrusion detection system with Nepenthes/Sebek honeypot software. This combination comes with client and server architecture so that various aspects of attack-oriented records with analytical capabilities are provided. Network administrators will receive warning notices when the entire network under monitoring was attacking. To reduce the burden on the deployment of distributed early warning system, we also implemented the system on the live USB and our system can be easily installed with high portability and plug-and-play features.