• DocumentCode
    3279818
  • Title

    An intrusion-tolerant firewall design for protecting SIEM systems

  • Author

    Garcia, M.A. ; Neves, Nuno ; Bessani, Alysson

  • Author_Institution
    Fac. of Sci., Univ. of Lisbon, Lisbon, Portugal
  • fYear
    2013
  • fDate
    24-27 June 2013
  • Firstpage
    1
  • Lastpage
    7
  • Abstract
    Nowadays, organizations are resorting to Security Information and Event Management (SIEM) systems to monitor and manage their network infrastructures. SIEMs employ a data collection capability based on many sensors placed in critical points of the network, which forwards events to a core facility for processing and support different forms of analysis (e.g., report attacks in near real time, inventory management, risk assessment). In this paper, we will focus on the defense of the core facility components by presenting a new firewall design that is resilient to very harsh failure scenarios. In particular, it tolerates not only external attacks but also the intrusion of some of its components. The firewall employs a two level filtering scheme to increase performance and to allow for some flexibility on the selection of fault-tolerance mechanisms. The first filtering stage efficiently eliminates the most common forms of attacks, while the second stage supports application rules for a more sophisticated analysis of the traffic. The fault tolerance mechanisms are based on a detection and recovery approach for the first stage, while the second stage uses state machine replication and voting.
  • Keywords
    finite state machines; firewalls; information systems; software fault tolerance; system monitoring; SIEM system protection; component intrusion; core facility components; data collection capability; external attacks; failure scenarios; fault detection; fault recovery; fault tolerance mechanism; filtering stage; intrusion-tolerant firewall design; network critical points; network infrastructures management; network infrastructures monitoring; organizations; security information and event management system; sensors; state machine replication; traffic; two level filtering scheme; voting; Computer crashes; Computer crime; Fault tolerance; Fault tolerant systems; Protocols; Sensors; Firewall; Intrusion Prevention Systems; Intrusion Tolerance;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Dependable Systems and Networks Workshop (DSN-W), 2013 43rd Annual IEEE/IFIP Conference on
  • Conference_Location
    Budapest
  • ISSN
    2325-6648
  • Type

    conf

  • DOI
    10.1109/DSNW.2013.6615538
  • Filename
    6615538