Browse wiki

From Navigators

Jump to: navigation, search
Abstract Nowadays, organizations are resorting to S Nowadays, organizations are resorting to Security Information and Event Management (SIEM) systems to monitor and manage their network infrastructures. SIEMs employ a data collection capability based on many sensors placed in critical points of the network, which forwards events to a core facility for processing and support different forms of analysis (e.g., report attacks in near real time, inventory management, risk assessment). In this paper, we will focus on the defense of the core facility components by presenting a new firewall design that is resilient to very harsh failure scenarios. In particular, it tolerates not only external attacks but also the intrusion of some of its components. The firewall employs a two level filtering scheme to increase performance and to allow for some flexibility on the selection of fault-tolerance mechanisms. The first filtering stage efficiently eliminates the most common forms of attacks, while the second stage supports application rules for a more sophisticated analysis of the traffic. The fault tolerance mechanisms are based on a detection and recovery approach for the first stage, while the second stage uses state machine replication and voting. uses state machine replication and voting.
Author Miguel Garcia + , Nuno Ferreira Neves + , Alysson Bessani +
Booktitle Workshop on Systems Resilience in conjunction with the Conference on Dependable Systems and Networks  +
Document Document for Publication-garcia13siem.pdf +
Key Garcia13siem  +
Month jun  +
NumPubDate 2,013.06  +
Project Project:MASSIF +
ResearchLine Fault and Intrusion Tolerance in Open Distributed Systems (FIT) +
Title An intrusion-tolerant firewall design for protecting SIEM systems  +
Type inproceedings  +
Year 2013  +
Has improper value forThis property is a special property in this wiki. Url  +
Categories Publication  +
Modification dateThis property is a special property in this wiki. 22 July 2014 10:43:36  +
hide properties that link here 
  No properties link to this page.


Enter the name of the page to start browsing from.
Personal tools
Navigators toolbox