科技报告详细信息
Instrumented SSH
Campbell, Scott ; Campbell, Scott
Lawrence Berkeley National Laboratory
关键词: Modifications;    Intrusion Detection Systems;    Monitoring;    Production Computer Security;    Computer Security;   
DOI  :  10.2172/960441
RP-ID  :  LBNL-1941E
RP-ID  :  DE-AC02-05CH11231
RP-ID  :  960441
美国|英语
来源: UNT Digital Library
PDF
【 摘 要 】

NERSC recently undertook a project to access and analyze Secure Shell (SSH) related data. This includes authentication data such as user names and key fingerprints, interactive session data such as keystrokes and responses, and information about noninteractive sessions such as commands executed and files transferred. Historically, this data has been inaccessible with traditional network monitoring techniques, but with a modification to the SSH daemon, this data can be passed directly to intrusion detection systems for analysis. The instrumented version of SSH is now running on all NERSC production systems. This paper describes the project, details about how SSH was instrumented, and the initial results of putting this in production.

【 预 览 】
附件列表
Files Size Format View
960441.pdf 304KB PDF download
  文献评价指标  
  下载次数:16次 浏览次数:41次