Passive Network Discovery for Real Time Situation Awareness
نویسندگان
چکیده
Network security analysts are confronted with numerous ambiguities when interpreting alerts produced by security devices. Even with the increased accuracy of these tools, analysts still have to sort through a tremendous number of potential security events in order to maintain the desired level of assurance. This paper describes how passive network discovery and persistent monitoring can provide significant contextual information valuable to network security professionals responsible for protecting the network. Techniques discussed include the capability to discover active nodes, their operating systems, the role they carry out, their system uptime, the services they offer, the protocols they support, and their IP network configuration. An attractive feature of this approach is that it focuses on mechanisms that do not rely on access to user data. While this is rarely a concern for the intruder, it can be of the utmost importance to the security analyst. One of the main interests in using a passive approach is that the information gathering process has no impact on the bandwidth or on the monitored assets. This is in contrast with active scanning techniques that are often noisy and intrusive. Passive techniques can be used at all times, allowing near real-time awareness of the security posture of ever-changing networks, and thus helping network administrators remain in control and anticipate upcoming security problems. A network monitoring prototype has been developed to test the techniques described in this paper.
منابع مشابه
Shared Situation Awareness For Army Applications June 2003
The real-time manned-unmanned teaming of on-the-move Army assets will provide mobile commanders and warfighters with improved situation awareness from the sharing and fusion of heterogeneous distributed data sources information. Lockheed Martin Advanced Technology Laboratories (ATL) is improving situation awareness through three ATL-developed technologies: adaptive, modular, multisensor informa...
متن کاملAdvanced visualization platform for surgical operating room coordination: distributed video board system.
One of the major challenges for day-of-surgery operating room coordination is accurate and timely situation awareness. Distributed and secure real-time status information is key to addressing these challenges. This article reports on the design and implementation of a passive status monitoring system in a 19-room surgical suite of a major academic medical center. Key design requirements conside...
متن کاملIntegrating Social Media with Ontologies for Real-Time Crowd Monitoring and Decision Support in Mass Gatherings
Situation awareness plays an essential role in making real-time decisions in mass gatherings. In the last few years, social media data analysis has been proved to be an effective approach to enable and enhance situation awareness. Mass gathering events are dynamic and critical environments where thousands of people attend. During the event, there is a potential for injuries and other health haz...
متن کاملOptimal Sitting, Sizing, and Operation of Batteries and Passive Filters to Mitigate Over-voltage and Harmonic Problems in Distribution Networks with High Photovoltaic Penetration
Photovoltaic systems (PVs), despite their many advantages, may have effects such as power quality issues (voltage and harmonics increase), short-circuits level increase, protection issues, and transient stability for network. Some of these effects are due to the high PV penetration, which encounters the network with the over-voltage and harmonics problems. In this paper, the location, size and ...
متن کاملReal Time Validation of Online Situation Awareness Questionnaires in Simulated Approach Air Traffic Control
Measuring Situation Awareness to evaluate an operator’s ability to handle complex dynamic situations and the use of assistance systems have become a standard approach in Human Factors research. Ideally, the operator’s work should be supported by enabling and disabling assistance systems depending on how well they are currently able to keep track of the situation. On the one hand, if the situati...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2004