The Experts below are selected from a list of 777 Experts worldwide ranked by ideXlab platform
Hannes Hartenstein - One of the best experts on this subject based on the ideXlab platform.
-
Attacks on Dynamic Protocol Detection of Open Source Network Security Monitoring Tools
2020 IEEE Conference on Communications and Network Security (CNS), 2020Co-Authors: Jan Grashöfer, Christian Titze, Hannes HartensteinAbstract:Protocol detection is the process of determining the application layer protocol in the context of Network Security Monitoring, which requires a timely and precise decision to enable protocol-specific deep packet inspection. This task has proven to be complex, as isolated characteristics, like port numbers, are not sufficient to reliably determine the application layer protocol. In this paper, we analyze the Dynamic Protocol Detection mechanisms employed by popular and widespread open-source Network Monitoring tools. On the example of HTTP, we show that all analyzed detection mechanisms are vulnerable to evasion attacks. This poses a serious threat to real-world Monitoring operations. We find that the underlying fundamental problem of protocol disambiguation is not adequately addressed in two of three Monitoring systems that we analyzed. To enable adequate operational decisions, this paper highlights the inherent trade-offs within Dynamic Protocol Detection.
-
attacks on dynamic protocol detection of open source Network Security Monitoring tools
arXiv: Networking and Internet Architecture, 2019Co-Authors: Jan Grashöfer, Christian Titze, Hannes HartensteinAbstract:Protocol detection is the process of determining the application layer protocol in the context of Network Security Monitoring, which requires a timely and precise decision to enable protocol-specific deep packet inspection. This task has proven to be complex, as isolated characteristics like port numbers are not sufficient to reliably determine the application layer protocol. Hence, more dynamic detection approaches have been developed. In this paper, we analyze the Dynamic Protocol Detection mechanisms employed by popular and widespread open-source Network Monitoring tools. We show on the example of HTTP that all analyzed detection mechanisms are vulnerable to evasion attacks, which pose a serious threat to real-world Monitoring operations. We find that the underlying fundamental problem of protocol disambiguation is not adequately addressed in two of three Monitoring systems that we analyzed. To enable adequate operational decisions, this paper highlights the inherent trade-offs within Dynamic Protocol Detection.
-
CNSM - Towards Application of Cuckoo Filters in Network Security Monitoring
2018Co-Authors: Jan Grashöfer, Florian Jacob, Hannes HartensteinAbstract:In this paper, we study the feasibility of applying the recently proposed cuckoo filters to improve space efficiency for set membership testing in Network Security Monitoring, focusing on the example of Threat Intelligence matching. We present conceptual insights for the practical application of cuckoo filters and provide a cuckoo filter implementation that allows runtime configuration. To evaluate the practical applicability of cuckoo filters, we integrate our implementation into the Bro Network Security Monitor, compare it to traditional data structures and conduct a brief operational evaluation. We find that cuckoo filters allow remarkable memory savings, while potential performance trade-offs, caused by introducing false positives, have to be carefully evaluated on a case-by-case basis.
-
Towards Application of Cuckoo Filters in Network Security Monitoring
2018 14th International Conference on Network and Service Management (CNSM), 2018Co-Authors: Jan Grashöfer, Florian Jacob, Hannes HartensteinAbstract:In this paper, we study the feasibility of applying the recently proposed cuckoo filters to improve space efficiency for set membership testing in Network Security Monitoring, focusing on the example of Threat Intelligence matching. We present conceptual insights for the practical application of cuckoo filters and provide a cuckoo filter implementation that allows runtime configuration. To evaluate the practical applicability of cuckoo filters, we integrate our implementation into the Bro Network Security Monitor, compare it to traditional data structures and conduct a brief operational evaluation. We find that cuckoo filters allow remarkable memory savings, while potential performance trade-offs, caused by introducing false positives, have to be carefully evaluated on a case-by-case basis.
Jarno Salonen - One of the best experts on this subject based on the ideXlab platform.
-
ARES - Network Security Monitoring in a Small-Scale Smart-Grid Laboratory
2014 Ninth International Conference on Availability Reliability and Security, 2014Co-Authors: Matti Mantere, Sami Noponen, Pia Olli, Jarno SalonenAbstract:Smart grids are the next generation of electrical grids, enabling the better management and leveling of power consumption by suppliers. Via the use of automatic meter reading, smart grid also provides better information to the end-users, making it possible to enhance their energy consumption and adapt it according to the current energy price, availability and other factors. As the grid becomes more and more reliant to ICT and communication Networks, risks related to cyberSecurity and privacy have to be taken into account. The link between automatic meters and the distribution operator has to be protected from Security breaches that may lead to false billing and the transferred data has to be protected as it contains sensitive information about household and business behavior. In this article we present a limited state-of-the-art review as well as a Network Security Monitoring setup for small-scale laboratory that is in essence a small scale smart grid environment. We discuss about the challenges and threats that are possible in the smart grid environment and the feasibility of using Network Security Monitoring techniques that represent our work-in-progress research in this context.
-
Network Security Monitoring in a small-scale smart-grid laboratory
Proceedings - 9th International Conference on Availability Reliability and Security ARES 2014, 2014Co-Authors: Matti Mantere, Sami Noponen, Pia Olli, Jarno SalonenAbstract:Smart grids are the next generation of electrical grids, enabling the better management and leveling of power consumption by suppliers. Via the use of automatic meter reading, smart grid also provides better information to the end-users, making it possible to enhance their energy consumption and adapt it according to the current energy price, availability and other factors. As the grid becomes more and more reliant to ICT and communication Networks, risks related to cyberSecurity and privacy have to be taken into account. The link between automatic meters and the distribution operator has to be protected from Security breaches that may lead to false billing and the transferred data has to be protected as it contains sensitive information about household and business behavior. In this article we present a limited state-of-the-art review as well as a Network Security Monitoring setup for small-scale laboratory that is in essence a small scale smart grid environment. We discuss about the challenges and threats that are possible in the smart grid environment and the feasibility of using Network Security Monitoring techniques that represent our work-in-progress research in this context.
Richard Bejtlich - One of the best experts on this subject based on the ideXlab platform.
-
The Practice of Network Security Monitoring
Network Security, 2014Co-Authors: Chris Sanders, Jason Smith, Richard BejtlichAbstract:The first chapter is devoted to defining Network Security Monitoring and its relevance in the modern Security landscape. It begins by discussing the four domains of Security and then describes how Network Security Monitoring fits into them. Key Security terms are defined in route to comparing and contrasting traditional intrusion detection and modern Network Security Monitoring. The NSM Cycle and its components (collection, detection, and analysis) are introduced. Next, the role of the analyst is introduced, along with critical analyst skills and potential specializations. Next, techniques for promoting analyst success are described. Finally, the Security Onion distribution is introduced, along with step-by-step instructions on the installation, initial configuration, and testing of Security Onion.
-
the practice of Network Security Monitoring understanding incident detection and response
2013Co-Authors: Richard BejtlichAbstract:Network Security is not simply about building impenetrable walls determined attackers will eventually overcome traditional defenses. The most effective computer Security strategies integrate Network Security Monitoring (NSM): the collection and analysis of data to help you detect and respond to intrusions. In The Practice of Network Security Monitoring, Mandiant CSO Richard Bejtlich shows you how to use NSM to add a robust layer of protection around your Networks no prior experience required. To help you avoid costly and inflexible solutions, he teaches you how to deploy, build, and run an NSM operation using open source software and vendor-neutral tools. You'll learn how to: Determine where to deploy NSM platforms, and size them for the monitored Networks Deploy stand-alone or distributed NSM installations Use command line and graphical packet analysis tools, and NSM consoles Interpret Network evidence from server-side and client-side intrusions Integrate threat intelligence into NSM software to identify sophisticated adversaries There's no foolproof way to keep attackers out of your Network. But when they get in, you'll be prepared. The Practice of Network Security Monitoring will show you how to build a Security net to detect, contain, and control them. Attacks are inevitable, but losing sensitive data shouldn't be.
-
the tao of Network Security Monitoring beyond intrusion detection
2004Co-Authors: Richard BejtlichAbstract:"The book you are about to read will arm you with the knowledge you need to defend your Network from attackers-both the obvious and the not so obvious.... If you are new to Network Security, don't put this book back on the shelf! This is a great book for beginners and I wish I had access to it many years ago. If you've learned the basics of TCP/IP protocols and run an open source or commercial IDS, you may be asking 'What's next?' If so, this book is for you."i¾ i¾ i¾ i¾ i¾ i¾ i¾ i¾ i¾ -Ron Gula, founder and CTO, Tenable Network Security, from the Foreword"Richard Bejtlich has a good perspective on Internet Security-one that is orderly and practical at the same time. He keeps readers grounded and addresses the fundamentals in an accessible way." i¾ i¾ i¾ i¾ i¾ i¾ i¾ i¾ i¾ -Marcus Ranum, TruSecure"This book is not about Security or Network Monitoring: It's about both, and in reality these are two aspects of the same problem. You can easily find people who are Security experts or Network monitors, but this book explains how to master both topics." i¾ i¾ i¾ i¾ i¾ i¾ i¾ i¾ i¾ -Luca Deri, ntop.org"This book will enable Security professionals of all skill sets to improve their understanding of what it takes to set up, maintain, and utilize a successful Network intrusion detection strategy." i¾ i¾ i¾ i¾ i¾ i¾ i¾ i¾ i¾ -Kirby Kuehl, Cisco SystemsEvery Network can be compromised. There are too many systems, offering too many services, running too many flawed applications. No amount of careful coding, patch management, or access control can keep out every attacker. If prevention eventually fails, how do you prepare for the intrusions that will eventually happen?Network Security Monitoring (NSM) equips Security staff to deal with the inevitable consequences of too few resources and too many responsibilities. NSM collects the data needed to generate better assessment, detection, and response processes-resulting in decreased impact from unauthorized activities.In The Tao of Network Security Monitoring, Richard Bejtlich explores the products, people, and processes that implement the NSM model. By focusing on case studies and the application of open source tools, he helps you gain hands-on knowledge of how to better defend Networks and how to mitigate damage from Security incidents.Inside, you will find in-depth information on the following areas. The NSM operational framework and deployment considerations. How to use a variety of open-source tools-including Sguil, Argus, and Ethereal-to mine Network traffic for full content, session, statistical, and alert data. Best practices for conducting emergency NSM in an incident response scenario, evaluating Monitoring vendors, and deploying an NSM architecture. Developing and applying knowledge of weapons, tactics, telecommunications, system administration, scripting, and programming for NSM. The best tools for generating arbitrary packets, exploiting flaws, manipulating traffic, and conducting reconnaissance.Whether you are new to Network intrusion detection and incident response, or a computer-Security veteran, this book will enable you to quickly develop and apply the skills needed to detect, prevent, and respond to new and emerging threats.
Matti Mantere - One of the best experts on this subject based on the ideXlab platform.
-
ARES - Network Security Monitoring in a Small-Scale Smart-Grid Laboratory
2014 Ninth International Conference on Availability Reliability and Security, 2014Co-Authors: Matti Mantere, Sami Noponen, Pia Olli, Jarno SalonenAbstract:Smart grids are the next generation of electrical grids, enabling the better management and leveling of power consumption by suppliers. Via the use of automatic meter reading, smart grid also provides better information to the end-users, making it possible to enhance their energy consumption and adapt it according to the current energy price, availability and other factors. As the grid becomes more and more reliant to ICT and communication Networks, risks related to cyberSecurity and privacy have to be taken into account. The link between automatic meters and the distribution operator has to be protected from Security breaches that may lead to false billing and the transferred data has to be protected as it contains sensitive information about household and business behavior. In this article we present a limited state-of-the-art review as well as a Network Security Monitoring setup for small-scale laboratory that is in essence a small scale smart grid environment. We discuss about the challenges and threats that are possible in the smart grid environment and the feasibility of using Network Security Monitoring techniques that represent our work-in-progress research in this context.
-
HiCoNS - A module for anomaly detection in ICS Networks
Proceedings of the 3rd international conference on High confidence networked systems - HiCoNS '14, 2014Co-Authors: Matti Mantere, Mirko Sailio, Sami NoponenAbstract:Network Security Monitoring using machine learning algorithms is a topic that has been well researched and found to be difficult to use. We propose to use a specific approach in restricted IP Network environments and leverage the Network state information and information from individual connections for increased level of sensitivity. The approach is meant for use in restricted IP Networks which exhibit a level of determinism that enables the use of machine learning approach. In this work we use algorithm called Self-Organizing Maps. We introduce an implementation of self-organizing maps engine built on top of the Bro Network Security monitor. An implemented selection of initial features for the Self-Organizing Maps is provided and a sample sub-set is used when training a SOM lattice for Network data from an industrial control system environment. The anomaly detection prototype described in this paper is meant as a complementary mechanism, not a standalone solution for Network Security Monitoring.
-
Network Security Monitoring in a small-scale smart-grid laboratory
Proceedings - 9th International Conference on Availability Reliability and Security ARES 2014, 2014Co-Authors: Matti Mantere, Sami Noponen, Pia Olli, Jarno SalonenAbstract:Smart grids are the next generation of electrical grids, enabling the better management and leveling of power consumption by suppliers. Via the use of automatic meter reading, smart grid also provides better information to the end-users, making it possible to enhance their energy consumption and adapt it according to the current energy price, availability and other factors. As the grid becomes more and more reliant to ICT and communication Networks, risks related to cyberSecurity and privacy have to be taken into account. The link between automatic meters and the distribution operator has to be protected from Security breaches that may lead to false billing and the transferred data has to be protected as it contains sensitive information about household and business behavior. In this article we present a limited state-of-the-art review as well as a Network Security Monitoring setup for small-scale laboratory that is in essence a small scale smart grid environment. We discuss about the challenges and threats that are possible in the smart grid environment and the feasibility of using Network Security Monitoring techniques that represent our work-in-progress research in this context.
Po-hsien Shih - One of the best experts on this subject based on the ideXlab platform.
-
SC² - Optimal Placement of Network Security Monitoring Functions in NFV-Enabled Data Centers
2017 IEEE 7th International Symposium on Cloud and Service Computing (SC2), 2017Co-Authors: Chia-feng Wu, Po-hsien ShihAbstract:While infrastructure as a service (IaaS) provides benefits such as cost reduction, dynamic deployment and high availability for users, it also blurs the boundary between the internal and external Networks, causing Security threats such as insider attacks which cannot be observed by traditional Security devices in the Network boundary. Coordination of Network function virtualization (NFV) and software-defined Networking (SDN) is a promising approach to address this issue, and an optimal placement mechanism is necessary to minimize the computing resources for Network Security Monitoring. In this work, we present a mechanism of placing virtualized Network functions (VNFs) for Network Security Monitoring in a data center to watch communications between pairs of virtual machines (VMs) or between VMs and external hosts. The placement issue is modeled as the minimum vertex cover problem and the bin packing problem to optimize the number and positions of VNFs subject to the availability of computing resources and link capacity. We design a greedy algorithm to reduce the time complexity of the problems. A Mininet simulation evaluates this solution for various topology sizes and communication pairs. The experiments demonstrate that the VNF placement planned by this algorithm is close to optimality, but the execution time can be reduced significantly.
-
Optimal Placement of Network Security Monitoring Functions in NFV-Enabled Data Centers
2017 IEEE 7th International Symposium on Cloud and Service Computing (SC2), 2017Co-Authors: Chia-feng Wu, Po-hsien ShihAbstract:While infrastructure as a service (IaaS) provides benefits such as cost reduction, dynamic deployment and high availability for users, it also blurs the boundary between the internal and external Networks, causing Security threats such as insider attacks which cannot be observed by traditional Security devices in the Network boundary. Coordination of Network function virtualization (NFV) and software-defined Networking (SDN) is a promising approach to address this issue, and an optimal placement mechanism is necessary to minimize the computing resources for Network Security Monitoring. In this work, we present a mechanism of placing virtualized Network functions (VNFs) for Network Security Monitoring in a data center to watch communications between pairs of virtual machines (VMs) or between VMs and external hosts. The placement issue is modeled as the minimum vertex cover problem and the bin packing problem to optimize the number and positions of VNFs subject to the availability of computing resources and link capacity. We design a greedy algorithm to reduce the time complexity of the problems. A Mininet simulation evaluates this solution for various topology sizes and communication pairs. The experiments demonstrate that the VNF placement planned by this algorithm is close to optimality, but the execution time can be reduced significantly.