13.07.2015 Views

2002 - cesnet

2002 - cesnet

2002 - cesnet

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

HTTPS server. After the identity verification, every authorized person can accessall results of the audit of all machines that the person administers.Results are displayed in two forms:• only the latest audit results• comparison of the latest and reference audit results (reference data areusually represented by the previous session results).In addition, a brief unencrypted notification about the delivery of new auditresults to the HTTPS server is sent to administrators by e-mail, including a briefsummary of results for every machine tested.19.2 Intrusion Detection System – IDSThe second part of the project was the installation of a system for detecting theunauthorized access to the network (Intrusion Detection System). The selectedSNORT program, which can be freely distributed thanks to the GNU licence,is operating in the networks of Czech Academy of Sciences in Praha-Krč andTechnical University of Ostrava. The program is used particularly when a suspicionof attacks to other systems exists and for detecting network viruses and/orviruses spreading through e-mail.19.3 LaBreaLaBrea is a program inspired by the asphalt deposit in LaBrea (Los Angeles,California, USA), which has been working as a trap for victims passing by fortens of thousands of years.The LaBrea system can detect attempts to access nonexistent machines in alocal network – such attempts are usually caused by network viruses or hackerssearching for security holes. The LaBrea server responds to these queriesinstead of the nonexistent machines and establishes a connection with the attacker,while only a minimum data volume is transferred (typically 0.34 Bpswhen communicating with Windows NT systems). This connection lasts untilthe program or attacker realizes that “nothing is happening” and closes theconnection. This may take a very long time and, during this whole period, theattacker (or this attacker’s thread) cannot cause harm anywhere else.The LaBrea program has many other positive features. Network administratorswill welcome, among other things, that the program installation is quite simpleand requires virtually no attendance. The LaBrea program is generally assessedas a very efficient method for fighting network viruses (CodeRed, Nimda, etc.).194 High-speed National Research Network and its New Applications <strong>2002</strong>

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!