| Enriching network security analysis with time travel |
| Full text |
Pdf
(446 KB)
|
Source
|
Applications, Technologies, Architectures, and Protocols for Computer Communication
archive
Proceedings of the ACM SIGCOMM 2008 conference on Data communication
table of contents
Seattle, WA, USA
SESSION: Security I
table of contents
Pages 183-194
Year of Publication: 2008
ISBN:978-1-60558-175-0
Also published in ...
|
|
Authors
|
|
Gregor Maier
|
TU Berlin / DT Labs, Berlin, Germany
|
|
Robin Sommer
|
ICSI / LBNL, Berkeley, CA, USA
|
|
Holger Dreger
|
Siemens AG, Munich, Germany
|
|
Anja Feldmann
|
TU Berlin / DT Labs, Berlin, Germany
|
|
Vern Paxson
|
ICSI / UC Berkeley, Berkeley, CA, USA
|
|
Fabian Schneider
|
TU Berlin / DT Labs, Berlin, Germany
|
|
| Sponsors |
|
| Publisher |
|
| Bibliometrics |
Downloads (6 Weeks): 32, Downloads (12 Months): 352, Citation Count: 1
|
|
|
ABSTRACT
In many situations it can be enormously helpful to archive the raw contents of a network traffic stream to disk, to enable later inspection of activity that becomes interesting only in retrospect. We present a Time Machine (TM) for network traffic that provides such a capability. The TM leverages the heavy-tailed nature of network flows to capture nearly all of the likely-interesting traffic while storing only a small fraction of the total volume. An initial proof-of-principle prototype established the forensic value of such an approach, contributing to the investigation of numerous attacks at a site with thousands of users. Based on these experiences, a rearchitected implementation of the system provides flexible, highperformance traffic stream capture, indexing and retrieval, including an interface between the TM and a real-time network intrusion detection system (NIDS). The NIDS controls the TM by dynamically adjusting recording parameters, instructing it to permanently store suspicious activity for offline forensics, and fetching traffic from the past for retrospective analysis. We present a detailed performance evaluation of both stand-alone and joint setups, and report on experiences with running the system live in high-volume environments.
REFERENCES
Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.
| |
1
|
ANDERSON, E., AND ARLITT, M. Full Packet Capture and Offline Analysis on 1 and 10 Gb/s Networks. Tech. Rep. HPL-2006-156, HP Labs, 2006.
|
| |
2
|
ANTONELLI, C., CO, K., M FIELDS, AND HONEYMAN, P. Cryptographic Wiretapping at 100 Megabits. In SPIE 16th Int. Symp. on Aerospace Defense Sensing, Simulation, and Controls. (2002).
|
| |
3
|
|
| |
4
|
ClearSight Networks. http://www.clearsightnet.com.
|
| |
5
|
CNET NEWS. Another suspected NASA hacker indicted. http://www.news.com/2102-7350_3-6140001.html.
|
| |
6
|
CoMo. http://como.sourceforge.net.
|
 |
7
|
Evan Cooke , Andrew Myrick , David Rusek , Farnam Jahanian, Resource-aware multi-format network security data storage, Proceedings of the 2006 SIGCOMM workshop on Large-scale attack defense, p.177-184, September 11-15, 2006, Pisa, Italy
[doi> 10.1145/1162666.1162677]
|
 |
8
|
|
| |
9
|
|
 |
10
|
|
 |
11
|
George W. Dunlap , Samuel T. King , Sukru Cinar , Murtaza A. Basrai , Peter M. Chen, ReVirt: enabling intrusion analysis through virtual-machine logging and replay, Proceedings of the 5th symposium on Operating systems design and implementation Due to copyright restrictions we are not able to make the PDFs for this conference available for downloading, December 09-11, 2002, Boston, Massachusetts
[doi> 10.1145/1060289.1060309]
|
| |
12
|
ENDACE MEASUREMENT SYSTEMS. http://www.endace.com/, 2008.
|
 |
13
|
Jose M. Gonzalez , Vern Paxson , Nicholas Weaver, Shunting: a hardware/software architecture for flexible, high-performance network intrusion prevention, Proceedings of the 14th ACM conference on Computer and communications security, October 28-31, 2007, Alexandria, Virginia, USA
[doi> 10.1145/1315245.1315264]
|
| |
14
|
Intelica Networks. http://www.intelicanetworks.com.
|
| |
15
|
Stefan Kornexl , Vern Paxson , Holger Dreger , Anja Feldmann , Robin Sommer, Building a time machine for efficient recording and retrieval of high-volume network traffic, Proceedings of the 5th ACM SIGCOMM conference on Internet Measurement, p.23-23, October 19-21, 2005, Berkeley, CA
|
| |
16
|
|
| |
17
|
|
| |
18
|
|
| |
19
|
|
 |
20
|
Miroslav Ponec , Paul Giura , Hervé Brönnimann , Joel Wein, Highly efficient techniques for network forensics, Proceedings of the 14th ACM conference on Computer and communications security, October 28-31, 2007, Alexandria, Virginia, USA
[doi> 10.1145/1315245.1315265]
|
| |
21
|
|
| |
22
|
|
| |
23
|
SHANMUGASUNDARAM, K., MEMON, N., SAVANT, A., AND BRÖNNIMANN, H. ForNet: A Distributed Forensics Network. In Proc. Workshop on Math. Methods, Models and Architectures for Comp. Networks Security (2003).
|
| |
24
|
SOMMER, R. Viable Network Intrusion Detection in High-Performance Environments. PhD thesis, TU München, 2005.
|
| |
25
|
|
| |
26
|
VALLENTIN, M., SOMMER, R., LEE, J., LERES, C., PAXSON, V., AND TIERNEY, B. The NIDS Cluster: Scalable, Stateful Network Intrusion Detection on Commodity Hardware. In Proc. 10th Int. Symp. Recent Advances in Intrusion Detection (RAID) (2007).
|
 |
27
|
|
CITED BY
|
|
Mark Allman , Christian Kreibich , Vern Paxson , Robin Sommer , Nicholas Weaver, Principles for developing comprehensive network visibility, Proceedings of the 3rd conference on Hot topics in security, p.1-6, July 29, 2008, San Jose, CA
|
|