DocumentCode :
3501542
Title :
NVision-PA: A Process Accounting Analysis Tool with a Security Focus on Masquerade Detection in HPC Clusters
Author :
Ermopoulos, Charis ; Yurcik, William
Author_Institution :
Dept. of Comput. Sci., Illinois Univ., Urbana-Champaign, IL
fYear :
2006
fDate :
25-28 Sept. 2006
Firstpage :
1
Lastpage :
10
Abstract :
In the UNIX/Linux environment the kernel can log every command process created by every user with process accounting. Thus process accounting logs have many potential uses, particularly the monitoring and forensic investigation of security events. Previous work successfully leveraged the use of process accounting logs to identify a difficult to detect and damaging intrusions within high performance computing (HPC) clusters, masquerade attacks, where intruders pose as legitimate users with purloined authentication credentials. This paper incrementally advances the goal of more accurately identifying masqueraders on HPC clusters by seeking to identify features within command sets that distinguish masqueraders. To accomplish this goal, we created NVision-PA, a software tool which produces text and graphic statistical summaries describing input processing accounting logs. This research is both a promising next step toward creating a real-time masquerade detection sensor for production HPC clusters as well as providing another tool for system administrators to use for statistically monitoring and managing legitimate workloads in HPC environments
Keywords :
Linux; operating system kernels; security of data; software tools; statistical analysis; text analysis; workstation clusters; HPC clusters; Linux; NVision-PA; SSH identity theft; UNIX; cluster security; forensic investigation; graphic statistical summary; high performance computing clusters; process accounting analysis tool; process accounting logs; purloined authentication credentials; real-time masquerade detection sensor; security events; software tool; system administrators; text summary; Authentication; Forensics; Graphics; High performance computing; Kernel; Linux; Monitoring; Real time systems; Security; Software tools; SSH identity theft; cluster security; command behavior; high performance computing (HPC); masquerade detection; process accounting;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Cluster Computing, 2006 IEEE International Conference on
Conference_Location :
Barcelona
ISSN :
1552-5244
Print_ISBN :
1-4244-0327-8
Electronic_ISBN :
1552-5244
Type :
conf
DOI :
10.1109/CLUSTR.2006.311856
Filename :
4100362
Link To Document :
بازگشت