13.07.2015 Views

2002 - cesnet

2002 - cesnet

2002 - cesnet

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

in the network of AV ČR Praha-Krč, the program helped detect spreading ofnetwork viruses in shared directories of computers with the Windows OS. Thesystem has been tested with a Fast Ethernet adapter so far. In the next year, wewould like to test its performance with a gigabit adapter.The LaBrea system was successfully implemented at all three research workplacesof this project. The graph provided in Figure 19.1 shows how many externalattacks the system detected in a single small sub-network of the CESNETnetwork in Dejvice at the end of November <strong>2002</strong> and how many threads it managedto capture:Figure 19.1: Graph of attacks detected by the LaBrea systemThe LaBrea Report program installed in the Dejvice network sends results generatedby the LaBrea system to responsible persons once a week and notifiesthem about the probable existence of compromised machines in their network.The typical letter looks approximately like this (shortened version):To: (...)From: IDS Subject: [IDS021206.0042] Please check your network integrityDate: Mon, 6 Dec <strong>2002</strong> 10:36:08 +0100Dear Administrator,I have detected security hole probes coming from your IPor domain space. This means someone is probing the Internetlooking for security holes and this is a strong indicator thatsomeone or something is misusing your computing facilities.The person(s) doing this may be the owner(s) of account(s) atHigh-speed National Research Network and its New Applications <strong>2002</strong>197

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!