13.07.2015 Views

2002 - cesnet

2002 - cesnet

2002 - cesnet

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Moreover, the program was complemented with the LBbe and LBrep (LaBreaBackEnd and LaBrea Report) programs by the Dejvice project team members.LaBrea BackEnd will process the output file of the LaBrea program and createa number of files containing information on attacks to the protected network.The number of these files is minimized so that reports on all attacks, for whichthe same group of network or domain administrators is responsible, are providedin one letter. The number of these files can be also reduced by specifyingcommand line parameters. The number of queries to Whois servers performedwhen searching for information on responsible administrators is minimized aswell. The LaBrea Report program sends files created by LaBrea BackEnd toappropriate administrators and notifies them about the probable existence ofcompromised machines in their network.19.4 ResultsWe offer three alternatives of the security audit: using PTS, classic FE/BE, andnew FE/WBE.PTS provides the easiest way to run the NESSUS program with the possibility tochoose the configuration file used for every machine tested. The program itselfsends the audit results to appropriate administrators by e-mail.FrontEnd (FE) performs the inspection of machines in the IP address rangesspecified by a network administrator. The program creates a list of all machinesthat are to be audited, determines their statuses by their response type (Broadcast,Loss, OK, TimeOut, WrongResponse), records the reference status, reportsdifferences from the reference status (including potential changes in the reversedomain), and creates a list of machines that will be tested by NESSUS as well asa configuration file usable for BE or WBE. The program offers the possibility towork in the interactive or batch mode, select working directories (with differentconfigurations of tested network), and write out detailed debug reports.BackEnd (BE) maintains the secure distribution of the audit results. The programcreates a standalone file for every administrator containing the audit results forall administrators’ machines tested (every machine can have several differentadministrators). These encrypted files are then sent by the Rep program.Decode (DEC) is designed for decoding the audit results sent by the Rep program.WebBackEnd (WBE) distributes the audit results in a secured form in a way similarto that of BackEnd. However, this program uses a method that is substantiallyeasier for end users – the results are published on the https://spider.<strong>cesnet</strong>.cz/server.High-speed National Research Network and its New Applications <strong>2002</strong>195

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!