首页> 外文会议>2010 4th International Conference on Network and System Security >Luth: Composing and Parallelizing Midpoint Inspection Devices
【24h】

Luth: Composing and Parallelizing Midpoint Inspection Devices

机译:Luth:中点检查设备的组成和并行化

获取原文

摘要

The race for innovation is driving Internet evolution. Internet software developers have to create more complex systems while enduring the pressuring time to market. Therefore, end-host software have bugs, vulnerabilities and cannot be trusted. That's why, among others, network Intrusion Detection System (IDS), Intrusion Prevention System (IPS), firewall or other network devices monitor such software to prevent unexpected behaviors. However, their functionalities are limited by design, because they can only handle a configuration of predefined monolithic protocol layerings. In this paper we present Luth, a midpoint inspection device that relies on the composition and parallelization of predefined midpoint inspectors (MI). We present the main functionalities offered by its configuration language and interpreter. Finally, we benchmark a prototype implemented in OCaml. This prototype runs in the user space of a GNU/Linux operating system, by means of the libnet filter_queue library. We show how it efficiently inspects and filters DNS hidden-channels encapsulated into 20 GRE tunnels.
机译:创新竞赛正在推动互联网的发展。 Internet软件开发人员必须创建更复杂的系统,同时还要忍受压力的上市时间。因此,最终主机软件具有错误,漏洞并且不能被信任。这就是为什么除其他外,网络入侵检测系统(IDS),入侵防御系统(IPS),防火墙或其他网络设备会监视此类软件以防止意外行为的原因。但是,它们的功能受到设计的限制,因为它们只能处理预定义的整体协议分层的配置。在本文中,我们介绍了Luth,这是一种中点检查设备,它依赖于预定义的中点检查器(MI)的组成和并行化。我们介绍其配置语言和解释器提供的主要功能。最后,我们对在OCaml中实现的原型进行基准测试。该原型通过libnet filter_queue库在GNU / Linux操作系统的用户空间中运行。我们展示了它如何有效地检查和过滤封装在20个GRE隧道中的DNS隐藏通道。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号