Robin Sommer
International Computer Science Institute
robin@icsi.berkeley.edu http://www.icir.org
iCAST / TRUST Collaboration Year 2 - Kickoff Meeting Robin Sommer - - PowerPoint PPT Presentation
iCAST / TRUST Collaboration Year 2 - Kickoff Meeting Robin Sommer International Computer Science Institute robin@icsi.berkeley.edu http://www.icir.org Projects Overview Project 1 NIDS Evasion Testing in a Live Context Project 2
International Computer Science Institute
robin@icsi.berkeley.edu http://www.icir.org
iCAST / TRUST - Year 2 Kickoff
2
iCAST / TRUST - Year 2 Kickoff
3
iCAST / TRUST - Year 2 Kickoff
4
Tap
NIDS
iCAST / TRUST - Year 2 Kickoff
(“Be liberal in what you accept, and conservative in what you send.”)
5
iCAST / TRUST - Year 2 Kickoff
6
iCAST / TRUST - Year 2 Kickoff
1.
Systematically generate test-cases
2.
Evaluate a NIDS
7
Input Trace Test Case Generation NIDS Test Traces Output Analysis
Evasion Module Evasion Module
Evasion Modules
Expected Output
iCAST / TRUST - Year 2 Kickoff
1.
2.
8
iCAST / TRUST - Year 2 Kickoff
9
iCAST / TRUST - Year 2 Kickoff
10
iCAST / TRUST - Year 2 Kickoff
11
iCAST / TRUST - Year 2 Kickoff
12
Incorporating heterogeneous sources
iCAST / TRUST - Year 2 Kickoff
13
Analyst Server Router Desktop IDS
"Who accessed system X and also fetched URL Y?"
iCAST / TRUST - Year 2 Kickoff
For each connection, TM stores only the first few KB
Once available space is exhausted, TM expires oldest packets
14
iCAST / TRUST - Year 2 Kickoff
1. A high-volume stream of input that we want to archive & query 2. A rule how to separate more important input from less important input 3. An aging mechanism to expire old information when storage fills up
15
iCAST / TRUST - Year 2 Kickoff
connection_attempt, http_request, ssh_login
syslog, Apache, OpenSSH
16
iCAST / TRUST - Year 2 Kickoff
17
iCAST / TRUST - Year 2 Kickoff
18
Dispatcher Stream Query Engine Event Stream Query Manager Event Indices Event Archive Operator
iCAST / TRUST - Year 2 Kickoff
Devising example queries to understand applications
Evaluating existing database backends
Evaluating existing stream databases
19
iCAST / TRUST - Year 2 Kickoff
20
International Computer Science Institute
robin@icsi.berkeley.edu http://www.icir.org