Fahime Alizade & Rawi Ramdhan } Introduction Why scan the - - PowerPoint PPT Presentation

fahime alizade rawi ramdhan introduction
SMART_READER_LITE
LIVE PREVIEW

Fahime Alizade & Rawi Ramdhan } Introduction Why scan the - - PowerPoint PPT Presentation

Fahime Alizade & Rawi Ramdhan } Introduction Why scan the Internet? How to detect and prevent Research question } Methods Architecture Traffic generation Intrusion Detection Load balancing Access List


slide-1
SLIDE 1

Fahime Alizade & Rawi Ramdhan

slide-2
SLIDE 2

} Introduction

  • Why scan the Internet?
  • How to detect and prevent
  • Research question

} Methods

  • Architecture
  • Traffic generation
  • Intrusion Detection
  • Load balancing
  • Access List
  • Intrusion Prevention

} Conclusion

slide-3
SLIDE 3

Viruses (D)DOS Hackers Identify Traffic Data Analysis

slide-4
SLIDE 4

Software Open
 Source SNORT BRO IDS Closed
 Source SourceFire Cisco IPS Sensors

slide-5
SLIDE 5

} Can OpenFlow enabled switches be used for

dispersing traffic over multiple IDS?

} Is it possible to pre-calculate the

performance of an IDS with a given set of variables?

} Can BRO be used as an IPS?

slide-6
SLIDE 6
slide-7
SLIDE 7

} Generate traffic } Generate packets } Replay Recorded PCAP

slide-8
SLIDE 8
slide-9
SLIDE 9
slide-10
SLIDE 10
slide-11
SLIDE 11

} TCP SYN – 64 Bytes } Max. packet pps: ~ 1.800.000 } ~ 700 Mb/s } TCP SYN – 1518 Bytes } Max. packet pps: ~ 800.000 } ~ 10.000 Mb/s

Replay PCAP

slide-12
SLIDE 12

} 1000 Sessions per second } 10.000 Packets per second

slide-13
SLIDE 13

} Bro provides scalable open-source IDS using

3 different elements:

  • Manager
  • Proxy
  • Workers
slide-14
SLIDE 14

} Random selection Load balancer

slide-15
SLIDE 15

} Round-robin Load balancer

slide-16
SLIDE 16

} Weighted round-robin Load balancer

slide-17
SLIDE 17

} Load balancer module in Floodlight } Unknown unicast } StaticFlowEntryPusher module

  • Port based flows
  • Flow management in specific timespan
slide-18
SLIDE 18
  • 1. Triggered script

  • 2. Telnet/SSH
  • 3. Route/policy based routing
slide-19
SLIDE 19

} One of the most widely used open source IPS

solutions

} Operates as stand alone systems } No scalable, distributed solution provided as

IPS

slide-20
SLIDE 20

} Can OpenFlow enabled switches be used for

dispersing traffic over multiple IDS?

  • It all depends

} Is it possible to pre-calculate the performance of

an IDS with a given set of variables?

  • In theory yes, but in practice you have to consider a

number of input variables

} Can BRO be used as an IPS?

  • No technical limitations
  • Hybrid solution as an IDS in combination with IPS
slide-21
SLIDE 21