Bro: a system for detecting network intruders in real-time

Bro: a system for detecting network intruders in real-time
复制标题

DOI:
10.1016/s1389-1286(99)00112-7
复制
发表时间:
1999-12-14
期刊:
COMPUTER NETWORKS-THE INTERNATIONAL JOURNAL OF COMPUTER AND TELECOMMUNICATIONS NETWORKING
影响因子:
--
通讯作者:
Paxson, V
Paxson, V
中科院分区:
其他
文献类型:
--
作者:
Paxson, V

文献摘要

被引文献

相似文献

我们描述了Bro,这是一个独立的系统,通过被动监控入侵者流量传输的网络链路来实时检测网络入侵者。概述了系统的设计,强调高速(fdi速率)监控、实时通知、机制与策略的明确分离以及可扩展性。为了实现这些目标,Bro将其分为“事件引擎”和“策略脚本解释器”,前者将经过内核过滤的网络流量流减少为一系列高级事件,后者解释用专门语言编写的事件处理程序,用于表达站点的安全策略。事件处理程序可以更新状态信息、合成新事件、将信息记录到磁盘,并通过syslog生成实时通知。我们还讨论了一些试图破坏被动监控系统的攻击和防御措施,并详细介绍了Bro如何分析到目前为止集成到它中的六个应用程序:Finger, FTP, Portmapper, Ident, Telnet和Rlogin。该系统以源代码形式公开提供。(C) 1999 Elsevier Science B.V.版权所有
We describe Bro, a stand-alone system for detecting network intruders in real-time by passively monitoring a network link over which the intruder's traffic transits. We give an overview of the system's design, which emphasizes high-speed (FDDI-rate) monitoring, real-time notification, clear separation between mechanism and policy, and extensibility. To achieve these ends, Bro is divided into an 'event engine' that: reduces a kernel-filtered network traffic stream into a series of higher-level events, and a 'policy script interpreter' that interprets event handlers written in a specialized language used to express a site's security policy. Event handlers can update state information, synthesize new events, record information to disk, and generate real-time notifications via syslog. We also discuss a number of attacks that attempt to subvert passive monitoring systems and defenses against these, and give particulars of how Bro analyzes the six applications integrated into it so far: Finger, FTP, Portmapper, Ident, Telnet and Rlogin. The system is publicly available in source code form. (C) 1999 Elsevier Science B.V. All rights reserved.