Bro: a system for detecting network intruders in real-time

被引:980
作者
Paxson, V [1 ]
机构
[1] Univ Calif Berkeley, Lawrence Berkeley Lab, Berkeley, CA 94720 USA
[2] AT&T Ctr Internet Res, ICSI, Berkeley, CA USA
来源
COMPUTER NETWORKS-THE INTERNATIONAL JOURNAL OF COMPUTER AND TELECOMMUNICATIONS NETWORKING | 1999年 / 31卷 / 23-24期
关键词
network intrusion detection; passive network monitoring; network monitoring evasion; domain-specific languages;
D O I
10.1016/S1389-1286(99)00112-7
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
We describe Bro, a stand-alone system for detecting network intruders in real-time by passively monitoring a network link over which the intruder's traffic transits. We give an overview of the system's design, which emphasizes high-speed (FDDI-rate) monitoring, real-time notification, clear separation between mechanism and policy, and extensibility. To achieve these ends, Bro is divided into an 'event engine' that: reduces a kernel-filtered network traffic stream into a series of higher-level events, and a 'policy script interpreter' that interprets event handlers written in a specialized language used to express a site's security policy. Event handlers can update state information, synthesize new events, record information to disk, and generate real-time notifications via syslog. We also discuss a number of attacks that attempt to subvert passive monitoring systems and defenses against these, and give particulars of how Bro analyzes the six applications integrated into it so far: Finger, FTP, Portmapper, Ident, Telnet and Rlogin. The system is publicly available in source code form. (C) 1999 Elsevier Science B.V. All rights reserved.
引用
收藏
页码:2435 / 2463
页数:29
相关论文
共 30 条
[1]  
*AXENT TECHN, 1999, INTR AL
[3]  
*CISC SYST, 1999, NETR
[4]  
COMPTON CL, 1994, P INT C MULT COMP SY
[5]  
*INT SEC SYST INC, 1999, REALS
[6]  
JACOBSON V, 1989, TCPDUMP
[7]  
KANTOR B, 1991, 1282 RFC SRI INT NET
[8]  
MCCANNE S, P 1993 WINT USENIX C
[9]  
MCCANNE S, 1994, LIBPCAP
[10]   NETWORK INTRUSION DETECTION [J].
MUKHERJEE, B ;
HEBERLEIN, LT ;
LEVITT, KN .
IEEE NETWORK, 1994, 8 (03) :26-41