Intrusion Detection Using Open Source Tools

Total Page:16

File Type:pdf, Size:1020Kb

Intrusion Detection Using Open Source Tools Revista Informatica Economică nr.2(46)/2008 75 Intrusion Detection using Open Source Tools Jack TIMOFTE [email protected] We have witnessed in the recent years that open source tools have gained popularity among all types of users, from individuals or small businesses to large organizations and en- terprises. In this paper we will present three open source IDS tools: OSSEC, Prelude and SNORT. Keywords: Network security, IDS, IPS, intrusion detection, intrusion prevention, open source. ntroduction OSSEC (www.ossec.net) is an open source I The traditional form of securing the net- host-based intrusion detection system work, the firewall proved to be insufficient. (HIDS). Given the nature and the complexity of the According to their own website, "OSSEC is a attacks, new ways of protecting the network scalable, multi-platform, open source Host- had to be developed. Intrusion Detection Sys- based Intrusion Detection System (HIDS). It tems, or shortly IDS are tools to monitor the has a powerful correlation and analysis en- events occurring in a computer system or gine, integrating log analysis, file integrity network and detect signs of possible inci- checking, Windows registry monitoring, cen- dents, such as violation of computer security tralized policy enforcement, rootkit detection, policies, acceptable use policies or standard real-time alerting and active response. It security practices. An Intrusion Prevention runs on most operating systems, including System, or IPS in addition to detecting inci- Linux, OpenBSD, FreeBSD, MacOS, Solaris dents, can play an active role by attempting and Windows." to stop the possible incidents which are de- In the recent years, OSSEC has received sev- tected. The Intrusion Detection/Prevention eral awards. In 2007, it was placed on the Systems (IDPS) can be classified according first position in the Top 5 Open Security to different criteria. The NIST Guide to In- Tools in the enterprise by LinuxWorld. In trusion Detection and Prevention Systems 2006, OSSEC was voted as the second best (NIST 800-94), lists four main types: IDS tool by the survey conducted by the sec- - Network-Based, which monitor the net- tools.org website. Recently, OSSEC has work; been acquired by Third Brigade, but accord- - Wireless - monitor wireless network traffic; ing to the press release, OSSEC will remain - Network Behavior Analysis (NBA) - which open source. examine the network traffic to identify The OSSEC HIDS can be installed as a threats like denial of service attacks and stand-alone tool to monitor one host or can malware; be deployed in a multi-host scenario, one in- - Host-Based - monitor a single host and the stallation being the server and the others as events occurring within that host. agents. The server and agents communicate According to the way an IDPS detect the in- securely using encryption. cidents, they can be classified into three cat- OSSEC also has intrusion prevention fea- egories: signature-based, anomaly-based and tures, being able to react to specific events or stateful protocol analysis, but most IDPS sys- set of events by using commands and active tems use multiple detection methodologies, responses. The system allows the creation of either separately or integrated, to improve the new commands which can be bound to performance. events. The system comes with some prede- Below we will briefly present a selection of fined active response tools, but the adminis- three open source tools: OSSEC, Prelude and trator can add others. SNORT. OSSEC was designed initially for Linux, but 76 Revista Informatica Economică nr.2(46)/2008 it evolved and since version 0.8 it also fea- them into the database, having several fea- tures a Windows agent, which can monitor tures such as relaying or filtering the events. the event log and other files. The Prelude LML is a signature-based log PRELUDE. Prelude (www.prelude- analyzer monitoring log files and received ids.com) is more than an open source IDS syslog messages for suspicious activity. It system - it is a framework which enables can handle events generated by a large set of other security applications to report to a cen- components, such as: Cisco PIX, Clamav, tralized system. ipchains, Netfilter, ipfw, Nokia ipso, Ms- It makes use of the IDMEF (Intrusion Detec- SQL, Nagios, NTsyslog, Pam, Portsentry, tion Message Exchange Format) standard Postfix, Proftpd, ssh etc. proposed by IETF, which allows defining the The PreludeDB library allows the developers events recorded by different sensors using a to use the Prelude IDMEF database, provid- single language. Prelude is considered a hy- ing an abstraction layer based upon the type brid system, since it allows the coexistence and the format of the database used to store of the event data from host-based, network- IDMEF alerts. based or wireless IDS agents, or simply any The last component, Prewikka is a console other security application. Existing security providing advanced features like contextual applications can be modified to use the Pre- filtering, aggregation, etc. Below we can see lude system, using the provided C, Python a simplified architecture with three sensors. and Perl frameworks. An interesting feature of Prelude is the possi- The main components of a Prelude system bility to “relay” the events between manag- are: the Prelude library (framework), the ers: in the following example, Branch A is Prelude Manager, the Prelude-LML, Prelu- relaying all the events to the Prelude Manag- deDB library and Prewikka (the console). er located in the Network Operation Center The Prelude library, Libprelude, is used to of the organization. Using this setup, Branch access the Prelude system and provides an A can only access the events recorded by API (Application Programming Interface) to sensors D, E and F, while the NOC (Network create events in the IDMEF (Intrusion Detec- Operation Center) can access the events gen- tion Message Exchange Format) format. It erated from all branches. can be used for failover and allows the crea- An interesting thing related to the three open tion of sensors that read the events received source tools presented in this article, is that by one or a set of prelude managers. they can be integrated: Prelude IDS frame- The Prelude Manager is a high-availability work has native support for both Snort and server which collects and normalizes infor- OSSEC. A list with all the external sensors mation from distributed sensors and stores which are supported natively is presented in Table 1. Fig.1. Prelude Simple Architecture Using the IDMEF API, additional own sen- SNORT. Snort (www.snort.org) is, without sors can be defined and programmed. In the doubt, one of the most popular open source PRELUDE documentation there is such an security tools. With millions of downloads, it example written in C. is used by individuals as well as large corpo- Revista Informatica Economică nr.2(46)/2008 77 rations or government organizations. The be faster than for most commercial IDS tools. first version was written in 1998 by Martin According to Jennifer Albornoz Mulligan, Roesch, who later founded Sourcefire. Since security researcher at Forrester Research, then, the product evolved both as features “Once the community writes those signa- and as portability: currently Snort is available tures, Sourcefire takes a little extra time to for most major platforms including Win- test them before it puts them out there, but dows, BSD, Solaris or Mac OS X. It is worth the process is still generally more responsive mentioning that Snort has an excellent sup- than others". This community ruleset comes port from the user community. This can be in addition to the official ruleset, released by considered as a big advantage since the the Sourcefire Vulnerability Research Team. availability of signatures for new attacks can Fig.2. Prelude Relaying Architecture Security Tool Description AuditD audit system Nepenthes detection and collection of worms and malware NuFW authenticating firewall OSSEC HIDS PAM authentication tasks PFLogger reports alerts from OpenBSD firewall Sancp information collection on network activity Samhain file integrity checker Snort NIDS Table 1. Native Support in Prelude IDS Snort can run in different modes, ranging and rules. from a simple sniffer to a IPS system: Snort Preprocessors allow the functionality - Sniffer mode; of Snort to be extended by allowing users - Packet Logger mode - logs packets to disk; and programmers add modular plug-ins. Pre- - NIDS mode - allows Snort to analyze net- processor code is run before the detection work traffic for matches against a user- engine is called, but after the packet has been defined rule set and to perform several ac- decoded. Such preprocessors exist for IP de- tions based on these matches; fragmentation (Frag3), TCP stream reassem- - Inline (IPS) mode - allows Snort to drop or bly (Stream4), HTTP, FTP, SMTP, SSH etc. pass packets based on the specific Snort Snort rules are used by the system to detect rules. incidents. Snort rules are divided into two Working as an IDS, Snort uses preprocessors logical sections, the rule header and the rule 78 Revista Informatica Economică nr.2(46)/2008 options. The rule header contains the rule's notification and logging when the system action, protocol, source and destination IP fires events. The supported types are text addresses and netmasks, and the source and (console), syslog and Unified 2 (a serialized destination ports information. The rule op- binary stream format). tion section contains alert messages and in- - The TCP Stream Reassembler – provide formation on which parts of the packet target-based services for reassembling TCP should be inspected to determine if the rule segments into normalized streams. action should be taken. The Data Source API is an interface between At this time, the latest stable version is the Data Source component and the Dis- 2.8.2.2. Currently a new beta version is under patcher.
Recommended publications
  • Instalación Y Configuración De Cortafuegos
    Tema 4. Seguridad y alta disponibilidad Instalación y configuración de cortafuegos Raquel Castellanos Crespo Instalación y configuración de cortafuegos Seguridad y alta disponibilidad Raquel Castellanos Crespo INDICE Cortafuegos - Concepto. Utilización de cortafuegos - Historia de los cortafuegos - Funciones principales de un cortafuegos: Filtrado de paquetes de datos, filtrado por aplicación, reglas de filtrado y registros de sucesos de un cortafuegos - Listas de control de acceso (ACL) - Ventajas y limitaciones de los cortafuegos - Políticas de cortafuegos - Tipos de cortafuegos: Clasificación por ubicación y por tecnología - Arquitecturas de cortafuegos - Pruebas de funcionamiento. Sondeos Cortafuegos software y hardware - Cortafuegos software integrados en los sistemas operativos - Cortafuegos software libres y propietarios - Distribuciones libres para implementar cortafuegos en maquinas dedicadas - Cortafuegos hardware. Gestión unificada de amenazas “Firewall UTM” (Unified Threat Management) 2 Tema 4. Seguridad y alta disponibilidad | Raquel Castellanos Crespo Instalación y configuración de cortafuegos Seguridad y alta disponibilidad Raquel Castellanos Crespo Concepto y utilización de cortafuegos Un cortafuegos (firewall en inglés) es una parte de un sistema o una red que está diseñada para bloquear el acceso no autorizado, permitiendo al mismo tiempo comunicaciones autorizadas. Se trata de un dispositivo o conjunto de dispositivos configurados para permitir, limitar, cifrar, descifrar, el tráfico entre los diferentes ámbitos sobre la base de un conjunto de normas y otros criterios. Los cortafuegos pueden ser implementados en hardware o software, o una combinación de ambos. Los cortafuegos se utilizan con frecuencia para evitar que los usuarios de Internet no autorizados tengan acceso a redes privadas conectadas a Internet, especialmente intranets. Todos los mensajes que entren o salgan de la intranet pasan a través del cortafuegos, que examina cada mensaje y bloquea aquellos que no cumplen los criterios de seguridad especificados.
    [Show full text]
  • The Science DMZ
    The Science DMZ Brian Tierney, Eli Dart, Eric Pouyoul, Jason Zurawski ESnet Supporting Data-Intensive Research Workshop QuestNet 2013 Gold Coast, Australia July 2, 2013 What’s there to worry about? © Owen Humphreys/National Geographic Traveler Photo Contest 2013 7/2/13 2 Lawrence Berkeley National Laboratory U.S. Department of Energy | Office of Science The Science DMZ in 1 Slide Consists of three key components, all required: “Friction free” network path • Highly capable network devices (wire-speed, deep queues) • Virtual circuit connectivity option • Security policy and enforcement specific to science workflows • Located at or near site perimeter if possible Dedicated, high-performance Data Transfer Nodes (DTNs) • Hardware, operating system, libraries all optimized for transfer • Includes optimized data transfer tools such as Globus Online and GridFTP Performance measurement/test node • perfSONAR Details at http://fasterdata.es.net/science-dmz/ Lawrence Berkeley National Laboratory U.S. Department of Energy | Office of Science Overview Part 1: • What is ESnet? • Science DMZ Motivation • Science DMZ Architecture Part 2: • PerfSONAR • The Data Transfer Node • Data Transfer Tools Part 3: • Science DMZ Security Best Practices • Conclusions Lawrence Berkeley National Laboratory U.S. Department of Energy | Office of Science The Energy Sciences Network (ESnet) A Department of Energy Facility Naonal Fiber footprint Distributed Team of 35 Science Data Network Internaonal Collaboraons Mul3ple 10G waves 5 Lawrence Berkeley National Laboratory U.S. Department of Energy | Office of Science ESnetSC Supports Supports Research DOE at More Office than 300 of Institutions Science Across the U.S. Universities DOE laboratories The Office of Science supports: 27,000 Ph.D.s, graduate students, undergraduates, engineers, and technicians 26,000 users of open-access facilities 300 leading academic institutions 17 DOE laboratories 6 Lawrence Berkeley National Laboratory U.S.
    [Show full text]
  • Intrusion Detection Systems (IDS)
    Intrusion Detection Systems (IDS) Adli Wahid Role of Detection in Security • Part of security monitoring o Violation of security policies o Indicators of compromise o Threat drive or Vulnerability driven o What’s happening on the network? • Rules o Detection is based on rules • Action • What do we do when detection happens? • Alert and Investigate • Drop / Block Perspective – Adversary Tactics and Techniques • Mitre Att&ck Framework https://attack.mitre.org • Tactics – what are the goals of the adversary? • Technique – how do they do it? • SubJect to: o Resources o Platforms • Can we used this knowledge for detection? o Observe Adversaries Behaviour o Techniques, Tactics and Procedures (TTPs) o Deploy in prevention, detection, response Your Adversaries Motives Infrastructure Targets Behaviour Your Assets Your Systems Reference: https://published-prd.lanyonevents.com/published/rsaus19/sessionsFiles/13884/AIR-T07-ATT%26CK-in-Practice-A-Primer-to-Improve-Your-Cyber-Defense-FINAL.pdf Reference: https://published-prd.lanyonevents.com/published/rsaus19/sessionsFiles/13884/AIR-T07-ATT%26CK-in-Practice-A-Primer-to-Improve-Your-Cyber-Defense-FINAL.pdf Making Your Infrastructure Forensics Ready • Detecting known or potentially malicious activities • Part of the incident response plan • If your infrastructure is compromised o Can you answer the questions: what happened and since when? o Can we ‘go back in time’ and how far back? • What information you you need to collect and secure? • Centralized logging Intrusion Detection Systems • An intrusion
    [Show full text]
  • SEGURIDAD Y ALTA DISPONIBILIDAD En Este Libro Se Abarcara La Asignatura De Servicios De Red E Internet Del Grado Superior De Informática
    SEGURIDAD Y ALTA DISPONIBILIDAD En este libro se abarcara la asignatura de servicios de red e internet del grado superior de informática. Escrito por: Nicolás Madrid Gallego Nicolás Madrid Gallego IES GREGORIO PRIETO CORTAFUEGOS SEGURIDAD Y ALTA DISPONIBILIDAD CORTAFUEGOS 2 SEGURIDAD Y ALTA DISPONIBILIDAD CORTAFUEGOS Contenido 1.- Concepto . Utilización de cortafuegos. ........................................................................... 3 2.-Historia de los cortafuegos ............................................................................................... 4 Primera generación – cortafuegos de red: filtrado de paquetes ................................ 5 Segunda generación – cortafuegos de estado ............................................................ 5 Tercera generación - cortafuegos de aplicación.......................................................... 6 Acontecimientos posteriores ......................................................................................... 6 1.3.-Funciones principales de un cortafuegos: Filtrado de paquetes de datos, filtrado por aplicación, Reglas de filtrado y registros de sucesos de un cortafuegos ................... 7 Filtrado de paquetes .............................................................................................................. 7 1.4.-Listas de control de acceso (ACL) .............................................................................. 10 1.5.-Ventajas y Limitaciones de los cortafuegos ..............................................................
    [Show full text]
  • Catalogueformationspythagorefd 2017.Pdf
    p.1 Pythagore F.D. : Apprendre à Apprendre Nouveautés 2017 : Pour plonger au coeur des technologies BigData, comprendre les concepts de NoSQL, d'indexation, de sharding, etc ... savoir concevoir les architecture ad-hoc et intégrer, déployer les solutions, nous proposons une gamme complète de formations, ateliers, classes virtuelles qui vont de l'introduction avec des stages comme « BigData, architecture et technologies », jusqu'à l'expertise sur des sujets comme la « Programmation R pour hadoop », ou le stage « Machine Learning : technologies et bonnes pratiques ». Nos domaines d'expertise : • Unix et Linux, et les applicatifs Apache, Openldap, Squid, Nagios, Zabbix, OCS/GLPI, puppet , chef... • la virtualisation et l'orchestration avec xen, kvm, lxc, Docker, et le cloud : cloudstack et openstack, openNebula, Cloudify, cobbler, etc ... • TCP/IP (IPv6, snmp, Architecture, Sécurité, Administration de réseaux IP, VoIP, ...) • Développement (langage C, Java, Jee, technologies Jee, JBoss, WebServices, PHP, Perl, Python , ...) et le développement sur mobiles android • les bases de données et le BigData avec NoSQL, Cassandra, MongoDB, Hadoop, ... Sur chacun de ces domaines, notre équipe possède un excellent niveau d'expertise couvrant l'ensemble du domaine, des fondamentaux aux outils les plus complexes : nos formations vont de l'introduction à Linux, à la Sécurité, la Haute Disponibilité, des concepts NoSQL à la programmation MapReduce Tous nos stages sont l'occasion de nombreuses mises en pratique et exercices de manière à permettre aux participants de bien assimiler les nouveaux concepts. Nos méthodes pédagogiques : Apprendre, concevoir, intégrer ... nous pensons que le meilleur moyen de comprendre les nouveaux concepts et les technologies est la mise en pratique. Nous organisons des ateliers, expériences, démonstrations, ..
    [Show full text]
  • A Brief Study and Comparison Of, Open Source Intrusion Detection System Tools
    International Journal of Advanced Computational Engineering and Networking, ISSN: 2320-2106, Volume-1, Issue-10, Dec-2013 A BRIEF STUDY AND COMPARISON OF, OPEN SOURCE INTRUSION DETECTION SYSTEM TOOLS 1SURYA BHAGAVAN AMBATI, 2DEEPTI VIDYARTHI 1,2Defence Institute of Advanced Technology (DU) Pune –411025 Email: [email protected], [email protected] Abstract - As the world becomes more connected to the cyber world, attackers and hackers are becoming increasingly sophisticated to penetrate computer systems and networks. Intrusion Detection System (IDS) plays a vital role in defending a network against intrusion. Many commercial IDSs are available in marketplace but with high cost. At the same time open source IDSs are also available with continuous support and upgradation from large user community. Each of these IDSs adopts a different approaches thus may target different applications. This paper provides a quick review of six Open Source IDS tools so that one can choose the appropriate Open Source IDS tool as per their organization requirements. Keywords - Intrusion Detection, Open Source IDS, Network Securit, HIDS, NIDS. I. INTRODUCTION concentrate on the activities in a host without considering the activities in the computer networks. Every day, intruders are invading countless homes On the other hand, NIDS put its focus on computer and organisations across the country via virus, networks without examining the hosts’ activities. worms, Trojans, DoS/DDoS attacks by inserting bits Intrusion Detection methodologies can be classified of malicious code. Intrusion detection system tools as Signature based detection, Anomaly based helps in protecting computer and network from a detection and Stateful Protocol analysis based numerous threats and attacks.
    [Show full text]
  • Ten Strategies of a World-Class Cybersecurity Operations Center Conveys MITRE’S Expertise on Accumulated Expertise on Enterprise-Grade Computer Network Defense
    Bleed rule--remove from file Bleed rule--remove from file MITRE’s accumulated Ten Strategies of a World-Class Cybersecurity Operations Center conveys MITRE’s expertise on accumulated expertise on enterprise-grade computer network defense. It covers ten key qualities enterprise- grade of leading Cybersecurity Operations Centers (CSOCs), ranging from their structure and organization, computer MITRE network to processes that best enable effective and efficient operations, to approaches that extract maximum defense Ten Strategies of a World-Class value from CSOC technology investments. This book offers perspective and context for key decision Cybersecurity Operations Center points in structuring a CSOC and shows how to: • Find the right size and structure for the CSOC team Cybersecurity Operations Center a World-Class of Strategies Ten The MITRE Corporation is • Achieve effective placement within a larger organization that a not-for-profit organization enables CSOC operations that operates federally funded • Attract, retain, and grow the right staff and skills research and development • Prepare the CSOC team, technologies, and processes for agile, centers (FFRDCs). FFRDCs threat-based response are unique organizations that • Architect for large-scale data collection and analysis with a assist the U.S. government with limited budget scientific research and analysis, • Prioritize sensor placement and data feed choices across development and acquisition, enteprise systems, enclaves, networks, and perimeters and systems engineering and integration. We’re proud to have If you manage, work in, or are standing up a CSOC, this book is for you. served the public interest for It is also available on MITRE’s website, www.mitre.org. more than 50 years.
    [Show full text]
  • Architecture of a Identity Based Firewall System
    ARCHITECTURE OF A IDENTITY BASED FIREWALL SYSTEM Nenad Stojanovski1 and Marjan Gušev2 1 Makedonski Telekom AD, Orce Nikolov BB, 1000 Skopje, Macedonia [email protected] 2 Faculty of Natural Sciences and Mathematics, Ss. Cyril and Methodius University, Arhimedova b.b., PO Box 162, 1000 Skopje, Macedonia [email protected] ABSTRACT Classic firewall systems are built to filter traffic based on IP addresses, source and destination ports and protocol types. The modern networks have grown to a level where the possibility for users’ mobility is a must. In such networks, modern firewalls may introduce such complexity where administration can become very frustrating since it needs the intervention of a firewall administrator. The solution for this problem is an identity based firewall system. In this paper we will present a new design of a firewall system that uses the user’s identity to filter the traffic. In the design phase we will define key points which have to be satisfied as a crucial milestone for the functioning of the whole Identity based firewall system. KEYWORDS Identity based firewalls, user identity, firewalls, network security, computer networks, firewall systems design 1. INTRODUCTION Classic firewall systems are built to filter traffic based on source and destination IP addresses, source and destination ports and protocol types[11]. As Information technology moves forward and advances, classic firewalls start to become very robust and unusable when it comes to the transparent user experience. The main problem that arises from using classic firewalls in a modern dynamic environment is that users have to be mobile and have access to their resources.
    [Show full text]
  • Cortafuegos Y Seguridad En El Internet”
    INSTITUTO POLITÉCNICO NACIONAL ESCUELA SUPERIOR DE INGENIERÍA MECÁNICA Y ELÉCTRICA UNIDADAD CULHUACAN TESIS “CORTAFUEGOS Y SEGURIDAD EN EL INTERNET” Que como prueba escrita de su examen profesional para obtener el Título de: Ingeniero en Comunicaciones y Electrónica Presenta: EDGAR VICENTE JIMÉNEZ ÁVILA Asesores Ing. Gustavo Mendoza Campeche Lic. Martha Guadalupe Hernández Cuellar México D.F FEBRERO 2014. A mi padre Que gracias a su apoyo moral y económico me ha apoyado para la culminación de mis estudios y al mismo tiempo a la realización de esta obra, y que gracias a sus consejos me han ayudado a ser una mejor persona. Gracias papá TE AMO. A mi madre Gracias al amor y cariño que me has brindado, a los consejos para superarme día a día, al apoyo económico y moral para concluir mis estudios y de esta manera ser un profesionista y servir a la sociedad. A mis hermanas Gracias madrecita. TE AMO. Que gracias al apoyo moral, ánimos, cariño y consejos brindados que me han servido para poder concluir satisfactoriamente mis estudios. Gracias Fabiola, Cindy, Miriam. A toda mi familia Especialmente a mi abuelita Teresa, mi tío Fredy Macario, mi abuelito Macario, mi abuelita Costa, mi tía Marlene, mi tío Alberto, que me han enseñado que la A Yanel dedicación es sinónimo de triunfó. Gracias Gracias a tus consejos, a tus ánimos para no darme por vencido tan fácilmente y todo el cariño que me has brindado, que día con día me hacen ser una persona de bien para la sociedad, gracias por estar a mi lado en los momentos de alegría y de tristeza.
    [Show full text]
  • Network Security Presentation
    http://bit.ly/2LamWxj Network Security & Performance Jason Zurawski Scott Chevalier [email protected] [email protected] ESnet / Lawrence Berkeley National Laboratory Indiana University International Networks Linux Cluster Institute (LCI) Introductory Workshop University of Oklahoma May 15-16, 2019 This document is a result of work by volunteer LCI instructors and is licensed under CC BY- NC-ND 4.0 (https://creativecommons.org/licenses/by-nc-nd/4.0/). National Science Foundation Award #1826994 https://epoc.global Science DMZ as Security Architecture • Allows for better segmentation of risks, more granular application of controls to those segmented risks. • Limit risk profile for high-performance data transfer applications • Apply specific controls to data transfer hosts • Avoid including unnecessary risks, unnecessary controls • Remove degrees of freedom – focus only on what is necessary • Easier to secure • Easier to achieve performance • Easier to troubleshoot Science DMZ Security • Goal : Disentangle security policy and enforcement for science flows from security for business systems • Rationale • Science data traffic is simple from a security perspective • Narrow application set on Science DMZ • Data transfer, data streaming packages • No printers, document readers, web browsers, building control systems, financial databases, staff desktops, etc. • Security controls that are typically implemented to protect business resources often cause performance problems • Separation allows each to be optimized Performance is a Core Requirement •Core information security principles • Confidentiality, Integrity, Availability (CIA) •In data-intensive science, performance is an additional core mission requirement: CIA PICA • CIA principles are important, but if the performance isn’t there the science mission fails • This isn’t about “how much” security you have, but how the security is implemented • Need to appropriately secure systems without performance compromises Motivations • The big myth: The main goal of the Science DMZ is to avoid firewalls and other security controls.
    [Show full text]
  • Pipenightdreams Osgcal-Doc Mumudvb Mpg123-Alsa Tbb
    pipenightdreams osgcal-doc mumudvb mpg123-alsa tbb-examples libgammu4-dbg gcc-4.1-doc snort-rules-default davical cutmp3 libevolution5.0-cil aspell-am python-gobject-doc openoffice.org-l10n-mn libc6-xen xserver-xorg trophy-data t38modem pioneers-console libnb-platform10-java libgtkglext1-ruby libboost-wave1.39-dev drgenius bfbtester libchromexvmcpro1 isdnutils-xtools ubuntuone-client openoffice.org2-math openoffice.org-l10n-lt lsb-cxx-ia32 kdeartwork-emoticons-kde4 wmpuzzle trafshow python-plplot lx-gdb link-monitor-applet libscm-dev liblog-agent-logger-perl libccrtp-doc libclass-throwable-perl kde-i18n-csb jack-jconv hamradio-menus coinor-libvol-doc msx-emulator bitbake nabi language-pack-gnome-zh libpaperg popularity-contest xracer-tools xfont-nexus opendrim-lmp-baseserver libvorbisfile-ruby liblinebreak-doc libgfcui-2.0-0c2a-dbg libblacs-mpi-dev dict-freedict-spa-eng blender-ogrexml aspell-da x11-apps openoffice.org-l10n-lv openoffice.org-l10n-nl pnmtopng libodbcinstq1 libhsqldb-java-doc libmono-addins-gui0.2-cil sg3-utils linux-backports-modules-alsa-2.6.31-19-generic yorick-yeti-gsl python-pymssql plasma-widget-cpuload mcpp gpsim-lcd cl-csv libhtml-clean-perl asterisk-dbg apt-dater-dbg libgnome-mag1-dev language-pack-gnome-yo python-crypto svn-autoreleasedeb sugar-terminal-activity mii-diag maria-doc libplexus-component-api-java-doc libhugs-hgl-bundled libchipcard-libgwenhywfar47-plugins libghc6-random-dev freefem3d ezmlm cakephp-scripts aspell-ar ara-byte not+sparc openoffice.org-l10n-nn linux-backports-modules-karmic-generic-pae
    [Show full text]
  • Evaluating the Availability of Forensic Evidence from Three Idss: Tool Ability
    Evaluating the Availability of Forensic Evidence from Three IDSs: Tool Ability EMAD ABDULLAH ALSAIARI A thesis submitted to the Faculty of Design and Creative Technologies Auckland University of Technology in partial fulfilment of the requirements for the degree of Masters of Forensic Information Technology School of Engineering, Computer and Mathematical Sciences Auckland, New Zealand 2016 i Declaration I hereby declare that this submission is my own work and that, to the best of my knowledge and belief, it contains no material previously published or written by another person nor material which to a substantial extent has been accepted for the qualification of any other degree or diploma of a University or other institution of higher learning, except where due acknowledgement is made in the acknowledgements. Emad Abdullah Alsaiari ii Acknowledgement At the beginning and foremost, the researcher would like to thank almighty Allah. Additionally, I would like to thank everyone who helped me to conduct this thesis starting from my family, supervisor, all relatives and friends. I would also like to express my thorough appreciation to all the members of Saudi Culture Mission for facilitating the process of studying in a foreign country. I would also like to express my thorough appreciation to all the staff of Saudi Culture Mission for facilitating the process of studying in Auckland University of Technology. Especially, the pervious head principal of the Saudi Culture Mission Dr. Satam Al- Otaibi for all his motivation, advice and support to students from Saudi in New Zealand as well as Saudi Arabia Cultural Attaché Dr. Saud Theyab the head principal of the Saudi Culture Mission.
    [Show full text]