Node, method and computer readable medium for inserting an intrusion prevention system into a network stack
Abstract
This record has no abstract on file.
Term
Term ended
Expired 25 October 2022, 3.9 years ago.
- Priority
- Filed
- Granted
- Expired
- Today
10 claims: 4 independent, 6 dependent
- 1Knoten ( 270 ) eines Netzes ( 100 ), das ein Einbruchserfassungssystem ( 91 ) betreibt, wobei der Knoten ( 270 ) folgende Merkmale aufweist:eine zentrale Verarbeitungseinheit ( 272 );ein Speichermodul ( 274 ) zum Speichern von Daten in einem maschinenlesbaren Format zur Wiedergewinnung und Ausführung durch die zentrale Verarbeitungseinheit ( 272 );eine Datenbank ( 277 ) zum Speichern einer Mehrzahl von maschinenlesbaren Netzausbeutungssignaturen ( 281A – 281N );ein Betriebssystem ( 275 ), das einen Netzstapel ( 90A ) aufweist, der einen Protokolltreiber ( 135 ), einen Medienzugriffs-Steuerungstreiber ( 145 ) und ein Exemplar des Einbruchserfassungssystems ( 91 ) aufweist, das als ein Zwischentreiber ( 140 ) implementiert ist und an den Protokolltreiber ( 135 ) und den Medienzugriffs-Steuerungstreiber ( 145 ) gebunden ist.
- 2Knoten ( 270 ) gemäß Anspruch 1, bei dem ein Rahmen, der auf einem Netzmedium ( 101 ), das mit dem Knoten ( 270 ) verbunden ist, empfangen wird, durch den Medienzugriffs-Steuerungstreiber ( 145 ) verarbeitet wird, wobei das Einbruchserfassungssystem ( 140 ) den verarbeiteten Rahmen direkt vom Medienzugriffs-Steuerungstreiber ( 145 ) empfängt.
- 3Knoten ( 270 ) gemäß Anspruch 2, bei dem das Einbruchserfassungssystem ( 140 ), das den verarbeiteten Rahmen empfängt, betreibbar ist, um den verarbeiteten Rahmen an den Protokolltreiber ( 135 ) zu leiten.
- 4Knoten ( 270 ) gemäß Anspruch 2, bei dem das Einbruchserfassungssystem ( 140 ), das den verarbeiteten Rahmen empfängt, den verarbeiteten Rahmen verwirft.
- 5Knoten ( 270 ) gemäß einem der Ansprüche 1 bis 4, bei dem ein Datagramm, das durch den Knoten ( 270 ) erzeugt wird, durch das Einbruchserfassungssystem ( 140 ) empfangen wird.
- 6Verfahren zum Ausführen einer Einbruchsprävention an einem Knoten ( 270 ) eines Netzes ( 100 ), wobei das Verfahren folgende Schritte aufweist:Binden eines Netzfilter-Dienstanbieters ( 140 ) an einen Medienzugriffs-Steuerungstreiber ( 145 ) eines Netzstapels ( 90A ) des Knotens ( 270 );und Binden des Netzfilter-Dienstanbieters ( 140 ) an einen Protokolltreiber ( 135 ) des Netzstapels ( 90A ) des Knotens ( 270 ).
- 7Verfahren gemäß Anspruch 6, das ferner ein Filtern durch den Netzfilter-Dienstanbieter ( 140 ) von allen Daten, die durch den Medienzugriffs-Steue ?page 12? rungstreiber ( 145 ) empfangen werden, vor dem Leiten der Daten an den Protokolltreiber ( 135 ) aufweist.
- 8Verfahren gemäß Anspruch 6 oder 7, das ferner ein Filtern durch den Netzfilter-Dienstanbieter ( 140 ) von allen Daten, die durch den Protokolltreiber ( 135 ) empfangen wurden, vor dem Leiten der Daten an den Medienzugriffs-Steuerungstreiber ( 145 ), aufweist.
- 9Computerlesbares Medium, auf dem ein Satz von Instruktionen, die ausgeführt werden sollen, gespeichert ist, wobei der Satz von Instruktionen, wenn dieselben durch einen Prozessor ( 272 ) ausgeführt werden, bewirkt, daß der Prozessor ( 272 ) ein Computerverfahren ausführt, wobei das Verfahren folgende Schritte aufweist:Binden eines Netzfilter-Dienstanbieters ( 140 ) an einen Medienzugriffs-Steuerungstreiber ( 145 ) eines Netzstapels ( 90A ) eines Betriebsystems ( 275 );und Binden des Netzfilter-Dienstanbieters ( 140 ) an einen Protokolltreiber ( 135 ) des Netzstapels ( 90A ) des Betriebssystems ( 275 ).
- 10Computerlesbares Medium gemäß Anspruch 9, bei dem das Binden des Netzfilter-Dienstanbieters ( 140 ) an den Medienzugriffs-Steuerungstreiber ( 145 ) und an den Protokolltreiber ( 135 ) auf die Initialisierung des Betriebssystems ( 275 ) hin erfolgt.
Independent claims10
44 paragraphs, as filed
The Invention relates to a node of a network, which operates an intrusion detection system, a method for performing an intrusion prevention at a node of a network, and a computer readable medium and, in other words, to network technologies and more particularly to a node, a method and a computer readable medium for introducing an intrusion prevention system in the network.
Network Exploitation attack tools, such as DoS attack Utilities (DoS = denial of service = Denial of Service) be technically more sophisticated, and because of the evolving Technologies they are easy to execute. Technically relatively uneducated Attackers can computer system impairments be involved in arranging or the same as one or more finish ducted Facilities are directed. A network system attack (herein is also referred to as penetration) is an unauthorized or malicious Using a computer or a computer network and may have hundreds or thousands of unprotected or otherwise impaired Internet node together in a coordinated attack on one or more selected targets include.
Network attack tools based on the client / server model to be a preferred Mechanism for performing decision with network attacks to target networks or devices become. High capacity machines in networks via insufficient safety feature, be attackers often used to launch distributed attacks therefrom. University Server typically have high connectivity and capacity, however, a relatively mediocre security on. Such networks also often have inexperienced or revised Network administrators, the sockets for involvement in network attacks make even more vulnerable.
Network Exploitation attack tools, having hostile attack applications such as denial of service utilities, the transmitting of over data a network media are responsible, often have a distinct "signature" or recognizable Pattern within the transmitted Data. The signature can be a recognizable sequence of special Packets and / or identifiable data including that within contains one or more packets. A signature analysis is often through a net-IPS (IPS = intrusion prevention system = intrusion prevention system) executed and can be used as a pattern matching algorithm can be implemented and other signature recognition capabilities and application monitoring utilities higher exhibit level. A simple signature analysis algorithm can after Find a specific string that enemy as a has been identified associated arrangement. Once the string has been identified within a network data stream, to the , Identified as one or more packets carrying the string "hostile" or exploitative are, and the IPS may then any one or more of a Number of measures like registering the identification of the frame, performing a countermeasure or performing another data archiving or protection measure, run.
The IPS include a technology that attempts exploitations against a to identify computer system or network of computer systems. Numerous types of IPS exist and are each generally considered either a network-based, host-based or node-based IPS classified.
The Network-based IPS devices are typically dedicated (or earmarked) systems at strategic locations on a Network are placed to data packets to investiga to determine chen order if they match attack signatures with known on. To Packages compare known attack signatures that use network-based IPS devices a mechanism which as a passive protocol analysis is designated to monitor all traffic on a network unobtrusively to sniff or and to events on a lower plane of a raw network traffic can be distinguished, capture. The network can exploitations by identifying Patterns or other observable characteristics of network frames detected will. Network-based IPS appliances examine the contents of data packets by parsing of network frames and packets and analyzing individual packets based on the protocols that are used on the network. A network-based IPS appliance monitors in an unobtrusive way network traffic, ie other network nodes may be the presence of Network-based IPS appliance not be aware of, and do, often not. A passive surveillance is normally a network-based IPS appliance by implementing a "promiscuous mode" access of a network interface device executed. A network interface device that operates in the indiscriminate mode copies packets directly from the network medium such as a coaxial cable, a 100baseT or other transmission medium, regardless of the destination node to which the packet is addressed. Thus, no simple method of transferring data over the Network transmission medium present, without the network-based IPS appliance the same examined and so may <?page 3?>the network-based IPS appliance the entire network traffic to which it is exposed, collect and analyze. After the identification of a suspicious packet, ie a Package, comprising the attributes that a known attack signature match, which monitors on a show by the network-based IPS appliance , an alarm can be generated thereby and a manager module IPS transferred be such that a Network expert security measures can implement. Network-based IPS appliances have to be additional advantage that they work in real time and as an attack while this happens, capture can.
The However, network-based IPS appliances may often a size Number of "false Positive ", ie incorrect diagnoses of an attack produce. False positives through network-based IPS appliances in part will be caused by errors, during the generated a passive traffic analysis, by detects the IPS be that in any number of network-supported protocols encoded can be and formatted. A content scanning by excessive a network-based IPS is not on an encrypted link possible, although the signature analysis based on protocol headers regardless run the may be whether the link encoded or not. In addition, the network-based IPS devices in high-speed networks frequently ineffective. As high speed networks become more common, the software-based, network-based IPS appliances that attempt all packets on a link to sniff, less and less reliable. Most significant is the fact that the network-based IPS appliances can not prevent attacks unless they are integrated into a firewall protection system and operate in conjunction with the same.
hostbased IPS detect intrusions by monitoring of application layer data. Host-based IPSs employ intelligent Agents to Computerprüfprotokolle on flashy activities to check and any change logs with an attack signature or compare user profiles. Host-based IPSs can also Key system files and executable Files for unexpected changes get out. Host-based IPSs are referred to as such, because the IPS utilities located on the system, which they are assigned to the same to protect. Host-based IPSs typically employ surveillance techniques on application level, examine the application logs maintained by various applications will. For example, a host-based IPS a database engine, the failed access attempts and / or modifications to system configurations registered monitor. alarms can to a management node in the identification of events come, read from the database log, as striking have been identified. Host-based IPS generally produce very little false positives. Host-based IPS, as protocol controller are, However, generally limited to identifying intrusions that have already taken place, and are also limited to events that occur on the single host. Because the protocol controller to a monitoring support of application protocols, will damage resulting from the registered attack, generally up to been identified by the time of the attack by the IPS is, have already taken place. Some host-based IPS can burglar preventive Functions such as "hooking" (Hooking) or "capture" (Intercepting) of the operating system application programming interfaces, run, to the execution preventive Operations by an IPS based on an application layer activity that burglary related to seems to be running. Because a break, which is detected in this way, already any IPS has bypassed the lower levels, provides a host-based IPS a final layer of defense against network exploitation represents. However, the host-based IPS to capture network events at a lower level, such. as log events, not useful.
node-based IPS contact the intrusion detection and / or prevention technology on the System that protected becomes. An example of node-based IPS technologies is the Series intrusion detection (inline intrusion detection). A node-based IPS can at each node of the network to be protected, implemented be. The inline IPS (Inline IPS) have intrusion detection technologies in the protocol stack of the protected are embedded network node. Because the inline IPS within the Protocol stack is embedded, move both inbound and outgoing data through the inline IPS and a monitoring subjected by the same. A series IPS overcomes many of the weaknesses which network-based solutions inherent. As mentioned above is, the network-based solutions generally ineffective in monitoring of high speed networks due to the fact that the network-based solutions try to monitor all network traffic on a given link. Monitoring The Series intrusion prevention systems However, only the traffic that is directed to the node on which installed the inline IPS is. Thus, the attack packets inline IPS on a finish Decisions machine not physically handle because the package through the protocol stack of decisions to the finish must move device. An arbitrary neighborhood of Rei<?page 4?>hen-IPS by another package must completely "logical" Bypassing the IPS done, that an attack packet that avoids inline IPS, this must in do a way that causes the inline IPS the attack packet not or not properly identified. additionally provided, inline IPSs the host node with monitoring and detection capabilities a lower level, similar to those of a network IPS, and can send a Protocol analysis and signature match or other monitoring provide or restrict the host traffic on the lower level. The most important Advantage the inline IPS technologies offer, is that the detects attacks are while they happen. While the host-based IPS attacks by monitoring system logs determine involves a series intrusion detection to monitor a Found network traffic and isolating those packets in which was that they Part of an attack against the host server, and so allowing that this Inline IPS actually prevents the Attack is successful. If it has been determined that a Package is part of an attack, the inline IPS layer may sort the package and thus prevent the Package the upper layer of the protocol stack is reached where the attack packet a can cause damage - a Effect which creates a local firewall for the server essentially, hosting the inline IPS and the same protection against threats either from an external network such as the Internet, or from the Inside the network come. In addition, the inline IPS layer may within the protocol stack to be embedded in a layer where the Packets encrypted so have been that the Inline IPS works effectively on a network with encrypted links. additionally can monitor outgoing traffic the inline IPS, because both the inbound and outbound traffic, the each for a Server is determined and is taken by the same, of the inline IPS hosting, has to move through the protocol stack.
Although the benefits of inline IPS technologies are numerous, there are in the implementation of such a system has some disadvantages. The series intruder detection is generally processor intensive and the behavior of the node collection utility that hosting, affect. additionally can the inline IPS produce numerous false positive diagnoses attack. Further, the inline IPS systematic probing of a network capture, as one which is carried out by recognition attack utilities because only the traffic on the local server hosting the inline IPS, is monitored by.
Each the network-based, host-based and row-based IPS technologies has respective advantages that are described above, on. Ideally comprises an intrusion prevention system all mentioned above Intrusion detection strategies. Additionally, an IPS or have more event generation mechanisms identifiable Events to one or more administrative bodies report. An event may have an identifiable series of system or network conditions or they may comprise a single identified condition. An IPS may also include an analysis engine or module and can analyze events generated by the one or more Event generation mechanism be created. A storage module may be included within an IPS for storing data, associated with the break-related events. A countermeasure mechanism may also within the IPS for executing a measure includes be that a detected can thwart or deny exploitation.
The IPS are often prone for a Type of attack, which is generally referred to as "polymorphic attack". Polymorphic attacks generate abnormal or malignant streams of network traffic to the to hide attack before the IPS system. take Polymorphic attacks generally one of two forms: an introduction attack (Insertion Attck) or avoiding attack (Evasion Attack). An insertion attack includes a sending additional Data to the IPS system, which does not accept the attacked host. Content scanners are often bypassed in this way. An attack prevention causes a IPS system data by a number of methods of generating an Fragmentation errors, TTL manipulation (TTL = time-to-live = Time-to-live include) and / or other protocol distortion techniques may fall leaves. Both the prevention and the introduction of attack, and polymorphic Attacks generally, the characteristic in common that an IPS to be "misled" that the Behavioral response of a network stack in response to suspicious data which are obtained by the same, mispriced. Consequently, an attack on a finish Decisions nodes are addressed, without the IPS about Knows, whereby the security procedures are circumvented by the network-based running IPS can be, and an attack possible is that security weaknesses Decisions of the finish Node exploit.
The <patcit><text>GB 2317539 A</text></patcit> refers on a firewall for Internet access and in particular discloses a system and a method for controlling the flow of Internet network connections by a firewall with a network protocol stack, which an Internet Proto<?page 5?>Kollmann (IP) layer includes. A determination of the flag parameter of a connection request is running, including a network element identifier for parameter, where the call request comes. A request is generated and it is determined whether one of these Request appropriate rule exists. If this is the case, it is determined whether required by generally authentication becomes. If so, an authentication protocol is enabled and the connection is activated when the authentication protocol has been successfully completed.
The WO 9854644 A1 discloses a multilayer firewall system. This system ensures Security in a network node with security features includes, working in multiple protocol layers. Several network devices, such as Remote access devices, Routers, switches, repeaters and network cards, the security features have, are configured to implement the distributed contribute firewall functions in the network. By contributing the firewall functionality for many Layers of the network in a variety of network devices across will implement a well-known firewall. The multilayer firewall includes a tactic definition component that receives tactics data define how the firewall should behave. The multilayer firewall includes also a selection of network devices that are used, to realize the defined tactics. The safety functions, in this collection of network devices via the plurality of protocol layers effect of time, are the tactics definition component such coordinates that specific devices realize that part of the tactics of their part of the network concerns.
It An object of the present invention, a node, a method and a computer readable medium for introducing an intrusion prevention system to provide in a network stack.
These Object is achieved by a node according to claim 1, a method claim 6 or dissolved a computer readable medium claim 9.
According to a embodiment of the present invention, an a node of a network, which Intrusion detection system operates, the node a central Processing unit, a memory module for storing data in a machine readable format for retrieval and execution by the central processing unit, a database for storing a plurality of machine-readable network exploitation signatures, an operating system that has a network stack, the protocol driver a, a media access control driver and an instance of the intrusion detection system which is implemented as an intermediate driver and to the Protocol drivers and the media access control driver bound is created. According to a another embodiment of the present invention, a process for filtering data at a node of a network, the direct binding of an intrusion prevention system to a media access control driver comprises a network stack of a node of the network created. According to a still another embodiment of the present invention, a computer readable medium, having a plurality stored instructions, a set instructions for filtering network data to be executed shall include, where the set of instructions, when the same executed by a processor is, causes the Processor, a computer method for binding an intrusion prevention system with a media access control driver after initialization running an operating system of the computer together.
Preferred embodiments of the present invention are described below with reference to the accompanying drawings explained. Show it:
<figref idrefs="S31">1</figref> an exemplary arrangement to run a computer system impairment prior of the technique;
<figref idrefs="S32">2</figref> a comprehensive intrusion prevention system, the network-based and hybrid host-based and node-based intrusion detection technologies according to a embodiment the invention uses;
<figref idrefs="S32">3</figref> an exemplary network protocol stack according to the state of the technique;
<figref idrefs="S33">4</figref> a network node an example (instance) of an intrusion protection system application according to a embodiment the present invention may operate;
<figref idrefs="S34">5</figref> an exemplary network node can operate as a management node within a network, represented by the intrusion protection system according to one embodiment the present invention protected is;
<figref idrefs="S33">6</figref> an exemplary network stack with a burglary protection system in the same <?page 6?>the network layer imported is to polymorphic attacks according to a embodiment to prevent the present invention.
The preferred embodiment of the present invention and its advantages are described with reference on <figref idrefs="S31">1</figref> to <figref idrefs="S33">6</figref> of the drawings, where identical Numeral for uses identical and corresponding parts of the various drawings are best understood.
In <figref idrefs="S31">1</figref> is an exemplary Arrangement for carrying a computer system compromise shown, the example shown a simplified arrangement the distributed intrusion network <figref>40</figref> shows that typical for distributed System attacks is based on a target machine <figref>30</figref> directional are. An attack machine<figref>10</figref> an execution of a distributed Attack by any number of attackers attack agents <figref>20A</figref>-<figref>20N</figref> by one of many techniques, such as a remote control by the IRC robot applications, instruct. The attack agents<figref>20A</figref>-<figref>20N</figref>Which are also referred to as "zombies" and "attack agents" are generally computers that are available for public use or so impaired are that a distributed attack on the terminal a command an attack machine <figref>10</figref> be started can. Numerous types of distributed attacks can against a target machine <figref>30</figref> be started. The target machine<figref>30</figref> can a comprehensive damage by simultaneous attacks by the attack agents <figref>20A</figref>-<figref>20N</figref> suffer, and the attack agents <figref>20A</figref>-<figref>20N</figref> can the client application attack also damaged will. A distributed network intrusion, an additional exhibit layer of machines in an attack between the attack machine <figref>10</figref> and the attack agents <figref>20A</figref>-<figref>20N</figref> are involved. These intermediate machines are commonly referred to as "handlers" ( "handler") referred to and each handling device may include one or more agents attack <figref>20A</figref>-<figref>20N</figref> control. The arrangement for carrying out a computer system compromise it is shown is illustrative only, and numerous arrangements can affect which are as simple as a single attack machine <figref>10</figref>. a target machine <figref>30</figref> by z. B. sending a malicious Probing packet or other data to the target machine <figref>30</figref> impair should attack. The Zielmaschi ne can to a larger network be connected and this is also common, and an attack on the same by the attack machine <figref>10</figref> can damage to a large collection cause of computer systems, which are often located within the network.
A or more of three general techniques are typically implemented to protect a system in a computer system impairment contemplated target can be: network-based intrusion prevention systems, host-based intrusion prevention systems and node-based intrusion prevention systems, is as described above. Network-based IPS appliances are typically IPS-dedicated components at strategic Positions are placed on a network to network in a frame Attempt to determine whether they coincide with known attack signatures, to investigate. To compare packets with known attack signatures, use network-based IPS appliances a mechanism as a passive protocol analysis is referred to all traffic unobtrusively on a network to monitor to search through or and to events at a lower level that the raw network traffic can be distinguished, capture. Network exploitations can by identifying patterns or other observable characteristics detected by network frames will. The network-based IPS to examine the contents of data packets by parsing network frames and packets and analyzing individual packets based on the protocols on the network be used. monitored A network-based IPS appliance network traffic typically unremarkable, ie that other Network nodes via the Presence of network-based IPS appliance not be aware can and these are also common. Passive surveillance is normally carried by a network-based IPS appliance Implementation of a "promiscuous mode" access to a network interface device executed. A network interface device that operates in the indiscriminate mode copies the packages directly from the network medium such as a coaxial cable, a 100baseT or other transmission medium, regardless the determination device to which the packet is addressed. consequently there is no simple method for transferring data over the Network transmission medium, without the network-based IPS appliance same investigated, and then the network-based IPS device the entire network traffic, which they suspended is gathering and analyzing. After identification of a suspicious package, that is, a packet that has attributes of a known Attack signature match, the network-based IPS appliance on her monitored for appearance, an alarm can be generated by the network-based IPS appliance and is transmitted to a management node of the IPS, where security measures accomplished can or a network expert can perform a safety measure. Network-based IPS appliances have the additional Advantage of working in real time and can detect attacks, while occur the attacks just below, depending on the placement of the Network-based IPS device prevent the Decisions attack to the finish reached nodes. Network-based intrusion prevention system applications to attempt <?page 7?>to detect attacks that an external network such as the Internet originate by data intended for the entrance into the network are to be analyzed and can be a network firewall arranged together. The net frame can collected and a database of different attack signatures are compared. An alarm can be generated and to a management node, a corrective action performs and / or a network administrator about the detected attack informed, then a corrective action such as closing a Communication ports a firewall or performing any other security procedure can perform, transmit will. The automated security measures may also after detecting an attack to be carried out by a network-based IPS appliance, if the application is integrated into a firewall or training in con with the same working. Typically, the network-based intrusion prevention system applications at or near the border of the network, which is protected, is placed. In addition, a network-based IPS appliance ideal for implementing a state-based IPS Safety, the accumulation and storing identified, flashy attack packets that are not "atomic" identified can, ie by a single network packet requires. For example, are not TCP SYN flood attacks be identifiable by a single TCP SYN packet, but Rather generally by accumulating a count identified from TCP SYN packets a predefined threshold opposite to exceed a defined period. A network-based IPS appliance is therefore an ideal platform to implement a state-based signature detection because the network-based IPS appliance collect all such TCP SYN packets can that about himself move the local network medium, and thus the incidence of such events archive properly and can analyze.
The host-based intrusion prevention systems, also referred to as "log Wächter" detect intrusions by monitoring System Logs. General are the host-based Intrusion systems on the system that is to be protected. Host-based Intrusion prevention systems can Burglaries collect at the application level, such. as an analysis of database engine access attempts and changes to system configurations.
The node-based intrusion prevention systems include a monitoring a network activity at a specific node on the network from any other Node by analyzing frames that are received by the may be involved in an attack. The IPS system of the present Invention must preferably a hybrid IPS the node-based series intruder detection and a host-based intrusion detection at each node of a network protected by the IPS is.
In <figref idrefs="S32">2</figref> is a comprehensive intrusion prevention system shown, the network-based and hybrid host-based / node-based Intrusion detection technologies according to an embodiment uses of the invention. One or more networks<figref>100</figref> can the Internet <figref>50</figref> about a router <figref>45</figref> or other device interfaced be. In the illustrative example, the network<figref>100</figref> two Ethernet networks <figref>55</figref> and <figref>56</figref> on. The Ethernet network<figref>55</figref> has a Webinhaltsserver <figref>270A</figref> and a file transport protocol content server <figref>270B</figref> on. The Ethernet network <figref>56</figref> has a domain name server <figref>270C</figref>. a mail server <figref>270D</figref>, A database server <figref>270E</figref> and a file server <figref>270F</figref> on. A Brandmauer- / proxy router<figref>60</figref>. of between Ethernets <figref>55</figref> and <figref>56</figref> arranged is, provides for the various systems of the network <figref>56</figref> a safety and address resolution. A network-based IPS appliance <figref>80</figref> and <figref>81</figref> is in each case on both sides of Brandmauer- / Proxy Router <figref>60</figref> implemented the monitoring of attempted attacks on one or more elements of the Ethernet networks <figref>55</figref> and <figref>56</figref> to facilitate and to provide a record of successful attacks To facilitate that the Brandmauer- / proxy router <figref>60</figref> successful penetrate. Network-based IPS appliances<figref>80</figref> and <figref>81</figref> can each a database <figref>80A</figref> and <figref>81A</figref> of known attack signatures have (or, alternatively, be connected to the same), or rules, with which the network frames that were detected by comparing can. Alternatively, a single data base (not shown) within a network <figref>100</figref> Centrally be arranged, and network-based IPS appliances <figref>80</figref> and <figref>81</figref> can access the same. Accordingly. the network-based IPS appliance<figref>80</figref> all Packets from the Internet <figref>50</figref> in the network <figref>100</figref> enter and the Ethernet network <figref>55</figref> arrive, monitor. Likewise a network-based IPS appliance <figref>81</figref> all packets that pass through the Brandmauer- / proxy router <figref>60</figref> delivery to the Ethernet network <figref>56</figref> be happening, monitor and compare. An IPS management node <figref>85</figref> can the web <figref>100</figref> to be included, the configuration and management of IPS components in network <figref>100</figref> includes are to facilitate. Given the above-noted deficiencies Network-based intrusion prevention systems is preferably a hybrid host-based and node-based intrusion prevention system within each of the various nodes, such as the servers <figref>270A</figref>-<figref>270N</figref> (Herein are also referred to as "nodes"), the Ethernet network <figref>55</figref> and <figref>56</figref> in the secure network <figref>100</figref> implemented. The management node <figref>85</figref> can alarm messages from each node intra<?page 8?>half of the network <figref>100</figref> after the detection of an intrusion event by any of the network-based IPS appliances <figref>80</figref> and <figref>81</figref> and any the nodes of the network <figref>100</figref>On which a hybrid-agent-based and node-based IPS is implemented, received. In addition, each node <figref>270A</figref>-<figref>270F</figref> on local file system for archiving intrusion-related events, for generating burglar related messages and to store signature files, compared to which the local network frames Packets are examined, and / or use.
Preferably the network-based IPS appliances <figref>80</figref> and <figref>81</figref> dedicated Entities for monitoring network traffic to the associated Ethernets <figref>55</figref> and <figref>56</figref> of network <figref>100</figref>, To the intrusion detection in high-speed networks facilitate, have the network-based IPS appliances <figref>80</figref> and <figref>81</figref> preferably a big Capture RAM for capturing packets as these on the respective Ethernet networks <figref>55</figref> and <figref>56</figref> arrive. additionally it is preferred that the Network-based IPS devices <figref>80</figref> and <figref>81</figref> each have hardware-based filter for filtering of network traffic, although IPS filtering by network-based IPS appliances <figref>80</figref> and <figref>81</figref> in a software may be included. In addition, the network-based IPS appliances<figref>80</figref> and <figref>81 </figref>z. For example, by request of the IPS management node <figref>85</figref> configured be to one or meh rere specific devices and not all to monitor devices on a common network. For example, a network-based IPS appliance <figref>80</figref> be instructed only to monitor the network traffic, of the web server <figref>270A</figref> is addressed.
The hybrid host-based / node-based intrusion prevention system technologies can to all nodes <figref>270A</figref>-<figref>270N</figref> on the Ethernet networks <figref>55</figref> and <figref>56</figref> be implemented, which can be taken by a network attack to the finish. In general, any Node of a reprogrammable computer having a CPU (CPU = Central Processing Unit = Central Processing Unit), a memory module, is operable to store a machine-readable code, which is retrievable and executable by the CPU, and may further contain various Peripheral devices such as a display monitor, a keyboard, a mouse and other device connected to the same are include. A storage medium such as a magnetic disk, a optical disk, or another component for storing Data is operable, may be coupled to the memory module may be and thereby accessible and one or more databases for archiving local intrusion events and intrusion event reports supply. An operating system may according to the memory module, z. B. , Loading the boats of the respective node and an instance a protocol stack and various software modules of the lower have plane for Tasks such as interfacing with one of a peripheral hardware, a Scheduling Tasks, an allocation of storage as well as other System tasks are required. Each node through the hybrid host-based and node-based IPS is the invention protected, accordingly has an IPS software application, which within the node is maintained as in a magnetic hard disk, by the operating system and retrievable by the central Processing unit executable is. additionally , each node executing a punching In the IPS-device, local database from which signature descriptions of documented Attacks fetched from memory and with a packet or frame of Data may be compared, is a match to capture therebetween. The detection a correspondence between a packet or frame at an IDS server may for executing any one or more of various security procedures to lead.
The with reference to <figref idrefs="S32">2</figref> described IPS can be implemented on any number of platforms be. Each hybrid host-based / node-based instance of the IPS application, herein is described, is preferably on a network node, such as a webserver <figref>270A</figref>Implemented, the one under control Operating system, such as Windows NT 4.0 is operated, which in a Main memory and stored on a central processing unit operates and tries to attacks directed to the host node are to be recognized. The special network<figref>100</figref>, this in <figref idrefs="S32">2</figref> is shown, is exemplary only and may have any number of network servers. Company and / or other large networks can typically have numerous individual systems that offer similar services. To the Example, a corporate network, hundreds of individual web servers, have mail servers, FTP servers and other systems, the common offer data services.
Each Operating system of a node that contains an occurrence of an IPS device includes, additionally has a network stack <figref>90</figref> to, in the <figref idrefs="S32">3</figref> is shown, the entry point the for frame defined by a finish Decisions node offline, z. B. be the Internet or Intranet received. The illustrated network stack <figref>90</figref> provides the well-known Windows NT (TM) -Systemnetzprotokollstapel represents and is selected been to discussing and understanding the invention easier. It is noted, however, that the Invention not limited to a specific implementation of the illustrated Netzsta pels <figref>90</figref> limited is, but rather on the stack <figref>90</figref>. <?page 9?>the described is to understand the invention easier. Network stack<figref>90</figref> has a TDI (TDI = transport driver interface = Transport Driver Interface) <figref>125</figref>. a transport driver <figref>130</figref>, A protocol driver <figref>135</figref> and a MAC driver (MAC = media access control = Media Access Control) <figref>145</figref> on, of the physical medium <figref>101</figref> interfaced is. The transport driver interface<figref>125</figref> is working, the transport driver <figref>130</figref> with the file system drivers higher interfaced to connect plane. Accordingly allows the TDI <figref>125</figref> the operating system drivers, such as the Netzumleitern, to activate a session or to the appropriate protocol driver <figref>135</figref> to tie. Consequently, a redirector on the appropriate protocol, z. B. a UDP, TCP, NetBEUI or other network or transport layer protocol, access, which the diverter is made protocol independent. The protocol driver<figref>135</figref> generated Data packets from the computer, the network protocol stack to <figref>90</figref> hosting, to another computer or other device on the Network or another network via the physical medium <figref>101</figref> be sent. Typical protocols supported by an NT network protocol stack, have NetBEUI, TCP / IP, NWLink, DLC (DLC data link control = Data Link Control) and AppleTalk, although other transport and / or network protocols supports can be. A MAC driver <figref>145</figref>, Z. B. an ethernet driver, a token ring driver or another network operating drivers, allows a corresponding formatting and interfacing with the physical media <figref>101</figref>Such as a coaxial cable or another transmission medium.
The Skills the host-based IPS, the application monitoring file system events; a registration access; of successful security events; failed security events and a conspicuous process monitoring on. With network access applications such as egg nem Microsoft IIS and SQL Server, can Processes which are based on the same, also monitored will.
Burglaries can on a special IPS host by implementing node-based monitoring technologies series (Inline monitoring technologies) be prevented. The inline IPS (in-line IPS) is preferably including as part of a hybrid host-based / node-based IPS, although it independently be implemented from any host-based IPS system can. The inline IPS analyzes the packets received on host node are, and leads signature analysis thereof against a database of known Signatures by a network layer filtering.
In <figref idrefs="S33">4</figref> is a network node <figref>270</figref> illustrated, the an instance of an IPS application <figref>91</figref> can operate and may operate as an IPS server. The IPS appliance<figref>91</figref> can as a three-layered IPS, as in a co-pending US application entitled "Method, Computer Readable Medium, and Node for a Three-Layered Intrusion Prevention System for Detecting Network exploits "which, simultaneously with the application whose priority herein is claimed, was filed and assigned to the same owner may be, was described, implemented and a server application and / or have a client application. The network node<figref>270</figref> has generally a CPU <figref>272</figref> and a memory module <figref>274</figref> on, is operable to store a machine-readable code, of the CPU <figref>272</figref> about a bus is retrievable and executable (not shown). A storage media <figref>276</figref>Such as a magnetic disk, a optical disk, or another component, which is operable to store data, may be with a memory module <figref>274</figref> connected be thus be by the bus as accessible. An operating system<figref>275</figref> can in the memory module <figref>274</figref>, Z. B. after booting the node <figref>270</figref>. are loaded and an instance of the protocol stack <figref>90</figref> have and cause a Intrusion prevention system application <figref>91</figref> from storage medium <figref>276</figref> Loading.
A or more network exploitation rules, an exemplary form, the in co-pending Application entitled "Method, Node and Computer Readable Medium for Identifying Data in a Network Exploit ", which simultaneously filed herewith, is described, can be machine-readable compiled signatures and within a database <figref>277</figref> saved be that in the memory module <figref>274</figref> loadable, and can through the IPS device <figref>91</figref> to facilitate an analysis be retrieved from network frames and / or packets.
In <figref idrefs="S34">5</figref> is an exemplary Network nodes shown that as a management node <figref>85</figref> of IPS of a network <figref>100</figref> can work. The management node<figref>85</figref> has generally a central processing unit <figref>272</figref> and a memory module <figref>274</figref> , which are operable by a machine-readable to store code by the CPU <figref>272</figref> over a Bus is retrievable and executable (not shown). A storage media<figref>276</figref>. such as a magnetic disk, an optical disk, or another component, is operable to store data, the memory module can with <figref>274</figref> connected be and is characterized also accessible by bus. An operating system<figref>275</figref> can in the memory module <figref>274</figref>, Z. B. after booting the node <figref>85</figref>. are loaded and an instance of the protocol stack <figref>90</figref> exhibit. The operating system <figref>275</figref> is operable to an IPS management application <figref>279</figref> from storage medium <figref>276</figref> to pick up and the management applica<?page 10?>manure <figref>279</figref> in the memory module <figref>274</figref> load, where it through the CPU <figref>272</figref> is performed. The knot <figref>85</figref> preferably includes an input device <figref>281</figref>, as a keyboard, and an output device <figref>282</figref>As a Monitor which is connected to the same, on.
On Operator of the management node <figref>85</figref> , one or more text files <figref>277A</figref>-<figref>277N</figref> about the input device <figref>281</figref> enter. Each text file<figref>277A</figref>-<figref>277N</figref> can define a network-based exploitation and a logical description of a Attack signature and IPS instructions to run after a IPS evaluation a burglar-related event that the attack signature described is assigned to have. Each text file<figref>277A</figref>-<figref>277N</figref> can in a database <figref>278A</figref> on a storage medium <figref>276</figref> be saved and by a compiler <figref>280</figref> in a respective machine-readable signature file <figref>281A</figref>-<figref>281N</figref> compiled be that in a database <figref>278B</figref> is stored. Each the machine-readable signature files <figref>281A</figref>-<figref>281N</figref> has a binary logic alternates the attack signature, the respective in associated text file <figref>277A</figref>-<figref>277N</figref> described is on. An operator of management node<figref>85</figref> can the management node <figref>85</figref> through interaction with a client application IPS device <figref>279</figref> via an input device <figref>281</figref> periodically instruct one or more machine-readable signature files (the are also generally referred to herein as "signature files"), in the database <figref>278B</figref> stored, to a node or a plurality of nodes in the network <figref>100</figref> transferred to. Alternatively, the signature files <figref>281A</figref>-281N In a computer-readable Medium such as a compact disk, a magnetic disk or a Be other portable storage device and stored on the node <figref>270</figref> the network <figref>100</figref> installed be. The application<figref>279</figref> is preferably operable to all such signature files <figref>281A</figref>-<figref>281N</figref> or one or more subsets same in to a node or a plurality of nodes Network <figref>100</figref> transferred to. Preferably, the IPS appliance <figref>279</figref> a graphical User interface on the output device <figref>282</figref> to the Facilitating input of commands in the same by an operator the knot <figref>85</figref> ready.
As mentioned above is an IPS device is often for one polymorphic attack vulnerable. The IPS identify hostile packets based on a predefined Signature, and due to the fact that the pre-defined signature an undesirable Effect as a loss of computing facilities, a giving of an th unauthorized access or other objectionable Systemverhal is assigned to polymorphic attacks are considered to be attacks, which essentially IPS perception of the response of the target system Decisions on the data obtained by IPS from the network stack of the target node Decisions were collected, change. If an IPS device <figref>91</figref> in a network-based IPS appliance is implemented, a passive monitoring is typically used since the network-based IPS appliance generally network access in case of power failure IPS does not lock. Therefore, an INS Target take a network-based IPS appliance in an attack often for a Attacker desirable - if the can be attacked and disabled network-based IPS appliance, is the network security at least substantially reduced, providing a much more vulnerable system for additional Attacks ready.
The polymorphic attacks that both Einbringungs- and avoid attacks include, try the protocol or signature analysis of the component bring network IPS to the behavioral response of the network stack on the data (inbound or outbound) received by the same be to identify false. An insertion attack generally comprises transmitting invalid packets in the network. An avoiding attack involving a yields of Differences between the signature analysis of IPS and functional Differences to the decision to finish System to the packets to the network-based IPS appliance without proper analysis same pass forward. For example, an IPS frequently evaluates the expected response to a specific package or a network framework Decisions of the finish Systems based on published Protocol standards that a specified response of a standardized network stack <figref>90</figref> define. In reality, the final number Manufacturer different operating systems, the variations of the standardized network stack <figref>90</figref> use, and each system may have different Deviations from published generate standards. Thus, an IPS appliance<figref>91</figref> a decision in terms of a treatment of a received packet or network frame based on an expected network stack behavior of the system, one IPS appliance <figref>91</figref> operates, make. Network stack<figref>90</figref>Which on a finish Decisions System works, but may have behavioral abnormalities caused by the IPS device <figref>91</figref> not be rated. The IPS is therefore not capable of a precise decision in terms of the actual Behavior of the network stack <figref>91</figref> to cut, and so can be exploited the knowledge of the security measures the IPS based on discrepancies between the expected behavior the network stack <figref>90</figref> thereof of the IPS and the actual behavior exploit.
In <figref idrefs="S33">6</figref> is an exemplary protocol stack <figref>90A</figref> shown in a Security System is introduced to polymorphic attacks according to an embodiment to verhin the invention<?page 11?>countries. Network stack<figref>90A</figref> has a TDI <figref>125</figref>, A transport driver <figref>130</figref>, A protocol driver <figref>135</figref> and one MAC driver <figref>145</figref> on coupled to the physical medium <figref>101</figref> interfaced is. The transport driver interface<figref>125</figref> is working, the transport driver <figref>130</figref> with the file system drivers higher connecting plane interfaced and allows the operating system drivers, at an appropriate protocol driver <figref>135</figref> to tie. The protocol driver<figref>135</figref> generates data packets that from the computer, the network protocol stack to <figref>90A</figref> hosting, to another computer or other device on the network or another network via the physical medium <figref>101</figref> be sent. The MAC driver<figref>145</figref>. z. B. an ethernet driver, a token ring driver or other Network driver enables an appropriate formatting and interfacing with the physical media <figref>101</figref>Such as a coaxial cable, a copper pair or other transmission medium. Network stack<figref>90A</figref> can additionally a dynamically linked Library <figref>115</figref> comprise a plurality of the subroutines allows that applications <figref>110</figref> in the application layer <figref>112</figref> the network stack <figref>90A</figref> on they can access, and facilitated because by linking with other applications. The dynamically linked Library <figref>115</figref> may be omitted, alternatively, and the functionality the same can be used in the operating system kernel, as in the art is understandable be installed.
On Intrusion prevention system network filter service provider <figref>140</figref>. is implemented as an intermediate driver that is above the physical media drive <figref>145</figref>, Such as the Ethernet driver, token ring driver, etc. installed and attached to the same. The intrusion prevention system network filter service provider<figref>140</figref> is preferably also to the protocol driver <figref>135</figref> bound. Thus, All machine-readable signature files in the database <figref>277</figref> to chat be opposite thereby the incoming and outgoing frames are validated. The intrusion prevention system network filter service provider<figref>140</figref> becomes preferably on both the media access control driver <figref>145</figref> as also the protocol driver <figref>135</figref> at system initialization or booting the operating system of the node that the IPS Filter Service Provider <figref>140</figref> hosting, bound. The IPS network filter service provider<figref>140</figref> provides filtering at the lower levels, to the suppression of network attacks to facilitate the "atomic" network attacks, network protocol level attacks, have an IP port filtering, but are not limited to the same, and also serves to facilitate collecting network statistics. Consequently, IPS observed by implementing a filtering service provider <figref>140</figref> of IPS at the network layer of the network stack <figref>90A</figref> identical data, the network stack handles. Consequently, the filter service provider<figref>140</figref> the execution IPS services based on a processing performance of Network stack evaluate.
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| GB2317539A | Cites | United Kingdom | Search report |
| WO9854644A1 | Cites | World Intellectual Property Organization (WIPO) | Search report |
| WO1998054644A1 | Cites | World Intellectual Property Organization (WIPO) | Search report |
6 members in 3 offices
Priority claims5
| Document | Office | Kind | Date |
|---|---|---|---|
| 144501 | United States of America | A | |
| 144501 | United States of America | A | |
| 144501 | United States of America | – | |
| 10001445 | – | – | – |
| US20010001445 | – | – | – |
Members6
| Document | Office | Kind | |
|---|---|---|---|
| GB0224537D0 | United Kingdom | D0 | |
| US2003084319A1 | United States of America | A1 | |
| GB2382261A | United Kingdom | A | |
| DE10249888A1 | Germany | A1 | |
| GB2382261B | United Kingdom | B | |
| DE10249888B4This record | Germany | B4 |
4 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Ceased/non-payment of the annual feeCeased8339 | 8339 | |
| No opposition during term of oppositionOpposition8364 | 8364 | |
| Change in the person/name/address of the patent owner8327 | 8327 | |
| Request for examination as to paragraph 44 patent lawOP8 | OP8 |
Numbers
- Publication
- 10249888
- Publication, DOCDB
- 10249888
- Publication, EPODOC
- DE10249888
- Application
- 10249888
- Application, DOCDB
- 10249888
- Application, EPODOC
- DE2002149888
Titles2
- German
- Knoten eines Netzes, das ein Einbruchserfassungssystem betreibt, Verfahren zum Ausführen einer Einbruchsprävention an einem Knoten eines Netzes, sowie computerlesbares Medium
- English
- Nodes of a network, which operates an intrusion detection system, method of performing intrusion prevention at a node of a network, and computer readable medium
Classification
- CPC, 5
- H04L63/1416
- H04L69/325
- H04L69/329
- H04L69/32
- H04L9/40
- IPC, 2
- H04L29 06
- H04L29 08