DocumentCode :
3209146
Title :
MNEMOSYNE: designing and implementing network short-term memory
Author :
Vigna, Giovanni ; Mitchell, Andrew
Author_Institution :
Reliable Software Group, California Univ., Santa Barbara, CA, USA
fYear :
2002
fDate :
2-4 Dec. 2002
Firstpage :
91
Lastpage :
100
Abstract :
Network traffic logs play an important role in incident analysis. With the increasing throughput of network links, maintaining a complete log of all network activity has become a task that requires an enormous amount of resources. We propose an approach to network monitoring that mitigates the resource consumption problem while still providing effective support to evidence collection and incident analysis. The approach relies on a tool, called MNEMOSYNE, that maintains a sliding window containing the traffic that has been recently seen on a network link. MNEMOSYNE provides improved logging features, such as multiple streams, support for cross-stream queries, and dynamic remote reconfiguration. By integrating MNEMOSYNE with real-time intrusion detection capability, it is possible to provide incident analysis functionality and effective evidence collection, without having to maintain complete traffic logs. This paper describes the MNEMOSYNE tool, its architecture, and presents the results of the quantitative evaluation of its performance.
Keywords :
computer network management; real-time systems; security of data; telecommunication security; telecommunication traffic; MNEMOSYNE; computer network monitoring; cross-stream queries; dynamic remote reconfiguration; incident analysis; logging features; multiple streams; network security; network short-term memory; network traffic logs; performance evaluation; real-time intrusion detection; resource consumption problem; sliding window; Application software; Computer architecture; Computer network reliability; Data security; Forensics; Intrusion detection; Maintenance; Monitoring; Telecommunication traffic; Throughput;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Engineering of Complex Computer Systems, 2002. Proceedings. Eighth IEEE International Conference on
Conference_Location :
Greenbelt, MD, USA
Print_ISBN :
0-7695-1757-9
Type :
conf
DOI :
10.1109/ICECCS.2002.1181501
Filename :
1181501
Link To Document :
بازگشت