Detecting intruders on a campus network: might the threat be coming from within?

Detecting intruders on a campus network: might the threat be coming from within?
复制标题

检测校园网络上的入侵者:威胁是否来自内部?

DOI:
--
复制
发表时间:
2005
期刊:
Conference on User Services
影响因子:
--
通讯作者:
W. Opdyke
W. Opdyke
中科院分区:
--
文献类型:
--
作者:
Richard A. Henders;W. Opdyke

文献摘要

被引文献

相似文献

园区网络以及支持这些网络的信息技术组织正面临着规模和复杂性都在不断增加的安全威胁。学生、教师和(非学术)工作人员共同提供广泛的期望和挑战,以安全地提供支持。侵入性操作和安全挑战可能来自网络外部或内部。在这样的环境中,安全和信任可能很难维持。入侵检测是综合安全策略的重要组成部分,Snort已经成为流行和广泛安装的入侵检测系统。它充当网络数据包嗅探器,根据数据包内容与封装为规则的已知病毒签名的比较,可以启动操作,并在日志文件和/或数据库中记录与其相关的事件和信息。因为Snort检查网络上的所有数据包,所以可能会产生大量数据,特别是在管理员能够根据安装需要调整包含在52个单独文件中的规则集之前。这一过程可能会导致大量的虚假警报,这可能会导致真正的警报被忽视,该工具的生存能力受到质疑。本文总结了在北中学院内部网络上安装和实施Snort的工作,特别强调了对登录到MySQL数据库的数据的访问以及通过Perl脚本呈现数据。还提供了Perl脚本的输出和支持该输出的代码片段,作为未来工作的基础。
Campus networks, and the Information Technology organizations that support these networks, are facing security threats that are increasing in both size and complexity. Students, faculty and (non-academic) staff collectively provide a broad set of expectations and challenges to securely support. Intrusive actions and security challenges may originate outside or within a network. Security and trust can be difficult to maintain in such an environment. Intrusion detection is an important part of a comprehensive security strategy.Snort has become a popular and widely installed Intrusion Detection System (IDS). It functions as a network packet sniffer which, based on comparisons of packet contents with known virus signatures encapsulated as rules, can initiate action and record events and information related to them in a log file and/or database. Because Snort inspects all packets on a network, large amounts of data can be produced, especially until an administrator can tune the rules sets, contained in 52 separate files, to the needs of the installation. This process can lead to a large number of false alerts, which may cause real alerts to be overlooked and the viability of the tool to be questioned.This paper summarizes work with installation and implementation of Snort on a North Central College internal network, with special emphasis on access to data logged to a MySQL database as well as presentation of data through Perl scripts. Output of Perl scripts and code snippets supporting the output are also presented as basis for future efforts.