Bro: a system for detecting network intruders in real-time

被引:980
作者
Paxson, V [1 ]
机构
[1] Univ Calif Berkeley, Lawrence Berkeley Lab, Berkeley, CA 94720 USA
[2] AT&T Ctr Internet Res, ICSI, Berkeley, CA USA
来源
COMPUTER NETWORKS-THE INTERNATIONAL JOURNAL OF COMPUTER AND TELECOMMUNICATIONS NETWORKING | 1999年 / 31卷 / 23-24期
关键词
network intrusion detection; passive network monitoring; network monitoring evasion; domain-specific languages;
D O I
10.1016/S1389-1286(99)00112-7
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
We describe Bro, a stand-alone system for detecting network intruders in real-time by passively monitoring a network link over which the intruder's traffic transits. We give an overview of the system's design, which emphasizes high-speed (FDDI-rate) monitoring, real-time notification, clear separation between mechanism and policy, and extensibility. To achieve these ends, Bro is divided into an 'event engine' that: reduces a kernel-filtered network traffic stream into a series of higher-level events, and a 'policy script interpreter' that interprets event handlers written in a specialized language used to express a site's security policy. Event handlers can update state information, synthesize new events, record information to disk, and generate real-time notifications via syslog. We also discuss a number of attacks that attempt to subvert passive monitoring systems and defenses against these, and give particulars of how Bro analyzes the six applications integrated into it so far: Finger, FTP, Portmapper, Ident, Telnet and Rlogin. The system is publicly available in source code form. (C) 1999 Elsevier Science B.V. All rights reserved.
引用
收藏
页码:2435 / 2463
页数:29
相关论文
共 30 条
[21]  
PTACEK TH, 1998, INSERTION EVASION DE
[22]  
RANUM M, 1997, P LISA 97 USENIX 11
[23]  
Rekhter Y., 1996, RFC 1918
[24]  
SRINIVASAN R, 1995, 1832 RFC DDN NETW IN
[25]  
SRINIVASAN R, 1995, 1831 RFC DDN NETW IN
[26]  
STJOHNS M, 1993, 1413 RFC SRI INT NET
[27]  
*TOUCH TECHN INC, 1999, INTOUCH INSA
[28]  
WHITE GA, 1994, DIVERSITY, V10, P20
[29]  
Zhang Y, 1996, FASEB J, V10, P719
[30]  
ZIMMERMAN D, 1991, 1288 RFC SRI INT NET