ACM Home Page
Please provide us with feedback. Feedback
Enriching network security analysis with time travel
Full text PdfPdf (446 KB)
Source
Applications, Technologies, Architectures, and Protocols for Computer Communication archive
Proceedings of the ACM SIGCOMM 2008 conference on Data communication table of contents
Seattle, WA, USA
SESSION: Security I table of contents
Pages 183-194  
Year of Publication: 2008
ISBN:978-1-60558-175-0
Also published in ...
Authors
Gregor Maier  TU Berlin / DT Labs, Berlin, Germany
Robin Sommer  ICSI / LBNL, Berkeley, CA, USA
Holger Dreger  Siemens AG, Munich, Germany
Anja Feldmann  TU Berlin / DT Labs, Berlin, Germany
Vern Paxson  ICSI / UC Berkeley, Berkeley, CA, USA
Fabian Schneider  TU Berlin / DT Labs, Berlin, Germany
Sponsors
ACM: Association for Computing Machinery
SIGCOMM: ACM Special Interest Group on Data Communication
Publisher
ACM  New York, NY, USA
Bibliometrics
Downloads (6 Weeks): 32,   Downloads (12 Months): 352,   Citation Count: 1
Additional Information:

abstract   references   cited by   index terms   collaborative colleagues  

Tools and Actions: Request Permissions Request Permissions    Review this Article  
DOI Bookmark: Use this link to bookmark this Article: http://doi.acm.org/10.1145/1402958.1402980
What is a DOI?

ABSTRACT

In many situations it can be enormously helpful to archive the raw contents of a network traffic stream to disk, to enable later inspection of activity that becomes interesting only in retrospect. We present a Time Machine (TM) for network traffic that provides such a capability. The TM leverages the heavy-tailed nature of network flows to capture nearly all of the likely-interesting traffic while storing only a small fraction of the total volume. An initial proof-of-principle prototype established the forensic value of such an approach, contributing to the investigation of numerous attacks at a site with thousands of users. Based on these experiences, a rearchitected implementation of the system provides flexible, highperformance traffic stream capture, indexing and retrieval, including an interface between the TM and a real-time network intrusion detection system (NIDS). The NIDS controls the TM by dynamically adjusting recording parameters, instructing it to permanently store suspicious activity for offline forensics, and fetching traffic from the past for retrospective analysis. We present a detailed performance evaluation of both stand-alone and joint setups, and report on experiences with running the system live in high-volume environments.


REFERENCES

Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.

 
1
ANDERSON, E., AND ARLITT, M. Full Packet Capture and Offline Analysis on 1 and 10 Gb/s Networks. Tech. Rep. HPL-2006-156, HP Labs, 2006.
 
2
ANTONELLI, C., CO, K., M FIELDS, AND HONEYMAN, P. Cryptographic Wiretapping at 100 Megabits. In SPIE 16th Int. Symp. on Aerospace Defense Sensing, Simulation, and Controls. (2002).
 
3
 
4
ClearSight Networks. http://www.clearsightnet.com.
 
5
CNET NEWS. Another suspected NASA hacker indicted. http://www.news.com/2102-7350_3-6140001.html.
 
6
CoMo. http://como.sourceforge.net.
7
8
 
9
10
11
 
12
ENDACE MEASUREMENT SYSTEMS. http://www.endace.com/, 2008.
13
 
14
Intelica Networks. http://www.intelicanetworks.com.
 
15
 
16
 
17
 
18
 
19
20
 
21
 
22
 
23
SHANMUGASUNDARAM, K., MEMON, N., SAVANT, A., AND BRÖNNIMANN, H. ForNet: A Distributed Forensics Network. In Proc. Workshop on Math. Methods, Models and Architectures for Comp. Networks Security (2003).
 
24
SOMMER, R. Viable Network Intrusion Detection in High-Performance Environments. PhD thesis, TU München, 2005.
 
25
 
26
VALLENTIN, M., SOMMER, R., LEE, J., LERES, C., PAXSON, V., AND TIERNEY, B. The NIDS Cluster: Scalable, Stateful Network Intrusion Detection on Commodity Hardware. In Proc. 10th Int. Symp. Recent Advances in Intrusion Detection (RAID) (2007).
27


Collaborative Colleagues:
Gregor Maier: colleagues
Robin Sommer: colleagues
Holger Dreger: colleagues
Anja Feldmann: colleagues
Vern Paxson: colleagues
Fabian Schneider: colleagues