Intrusion detection in distributed systems, an approach based on taint marking

Intrusion detection in distributed systems, an approach based on taint marking
复制标题

分布式系统中的入侵检测,一种基于污点标记的方法

DOI:
--
复制
发表时间:
2013
期刊:
2013 IEEE International Conference on Communications (ICC)
影响因子:
--
通讯作者:
L. Mé
L. Mé
中科院分区:
--
文献类型:
--
作者:
Christophe Hauser;F. Tronel;C. Fidge;L. Mé

文献摘要

被引文献

相似文献

本文提出了一个基于污点标记的分布式入侵检测的新框架。我们的系统通过将污点标签附加到系统对象,例如文件,插座,插座,进程通信(IPC)摘要和内存映射等,跟踪聚集成组的多个主机的应用之间的信息流(即共享相同分布式信息流策略的一组)。 。标签是通过张贴网络数据包在网络上携带的。通过标记信息并定义用户和应用程序如何合法访问,更改或传输信息向其他受信任或不受信任的主机定义,为每个组定义了分布式信息流策略。与现有方法相反,在当前的方法中,信息通常以两个安全级别(低/高,公共/私人等)表示,我们的模型在分布式系统中标识了每个信息,并在细粒度中定义了它们的法律互动方式。托管商店和交换安全标签以同行方式与同行时尚,并且没有中央监视器。我们的ID在Linux内核中作为Linux安全模块(LSM)实现,并在商品硬件上运行标准软件,而无需修改。唯一值得信赖的代码是我们修改的操作系统内核。我们最终提出了在多个主机上运行的Web服务中入侵的方案,并显示我们的分布式ID如何在每个主机级别报告安全违规行为。
This paper presents a new framework for distributed intrusion detection based on taint marking. Our system tracks information flows between applications of multiple hosts gathered in groups (i.e. sets of hosts sharing the same distributed information flow policy) by attaching taint labels to system objects such as files, sockets, Inter Process Communication (IPC) abstractions, and memory mappings. Labels are carried over the network by tainting network packets. A distributed information flow policy is defined for each group at the host level by labeling information and defining how users and applications can legally access, alter or transfer information towards other trusted or untrusted hosts. As opposed to existing approaches, where information is most often represented by two security levels (low/high, public/private etc.), our model identifies each piece of information within a distributed system, and defines their legal interaction in a fine-grained manner. Hosts store and exchange security labels in a peer to peer fashion, and there is no central monitor. Our IDS is implemented in the Linux kernel as a Linux Security Module (LSM) and runs standard software on commodity hardware with no required modification. The only trusted code is our modified operating system kernel. We finally present a scenario of intrusion in a web service running on multiple hosts, and show how our distributed IDS is able to report security violations at each host level.