Build Linux security bastion host intrusion detection and warning

Source: Internet
Author: User
Article Title: Build a Linux security bastion for intrusion detection and early warning. Linux is a technology channel of the IT lab in China. Includes basic categories such as desktop applications, Linux system management, kernel research, embedded systems, and open source.
The importance of information infrastructure determines the necessity of network intrusion detection and early warning. When we need network warnings to defend the network just as we need radar to defend the airspace, we need to invest manpower, material resources, and financial resources to tackle the key technology of network warning, the development and development of practical network intrusion detection and early warning systems has become a necessary measure.
  
   I. Urgency of conducting research on Intrusion Detection Technology
All security threats may take attacks, intrusions, penetration, impact, control and destruction of networks and online information systems as an important means. Therefore, monitoring and auditing of destructive activities from the Internet is a prerequisite for prevention and an important and essential part for building an information security environment.
Early warning systems and intrusion detection technologies have been carried out in foreign countries, and illegal intrusion is monitored on important political, military, and economic networks. These systems play an important role in protecting information network security, discovering signs of intrusion attacks as soon as possible, and analyzing the technical means of intrusion attacks. In order to improve the protection capability of the information system, our country should fill this gap as soon as possible.
  
   Ii. diverse detection objects
Network intrusion activities are initiated by different types of individuals or organizations with different purposes, using different technologies, at different locations and times, and targeting different targets. Many differences and their combinations constitute the diversity of detection objects.
The Research on intrusion detection and early warning technologies should at least achieve the following multi-level objectives:
1. Make a comprehensive and systematic assessment of the security status and threats (including the source and extent of threats) of information infrastructure.
2. Take the threat source as the object, and conduct statistics, analysis and audit based on the time sequence, Action intention, threat scope and extent.
3. identify, track, record, classify and alert malicious code and illegal operations from external networks.
4. Provide technical support for the recovery of damaged networks and information systems.
  
   Iii. complexity of warnings
The harmful behaviors of networks are a series of complex activities, especially premeditated and organized network intrusions. Therefore, effective early warnings are complicated and difficult in technical implementation.
The complexity of warnings is as follows:
* Source Recognition;
* Determination of attempt;
* Determination of hazards and potential abilities;
* Network Technology tracking;
* Software design;
* Hardware adaptability.
According to our research, the following three problems need to be solved.
  
1. The intrusion technology is evolving
Relying on the research of network attack technology, network warning technology enhances the intrusion detection capability by tracking the development of intrusion technology. Intrusion methods involve vulnerabilities in all aspects of the operating system, such as system design defects, coding defects, system configuration defects, operation management defects, and even reserved backdoors in the system. There are a large number of hacker sites on the Internet, releasing a large number of system vulnerability information and exploring attack methods. Hackers all over the world can use these shared resources to research and spread attack methods, so that new attack methods can become the fastest intrusion weapon. What is even more worrying is that organized activities, foreign countries have combined information warfare techniques with nuclear weapons, biological and biological weapons to discuss them as a strategic deterrent, and the capabilities of Destructors, it is still a big unknown for us.
The development of intrusion technology poses great difficulties for early warning, especially for early warning systems based on intrusion pattern recognition. It is difficult to know all possible intrusion methods in advance. Therefore, an effective early warning system not only needs to identify known intrusion patterns, but also has the ability to deal with unknown intrusion patterns. Network warning technology is also keeping pace with the identified intrusion pattern, although it can greatly enhance network security, but this is not the only development direction. Intrusion detection technology is more effective in terms of monitoring abnormal network activity and normal network activity. At the same time, the early warning system should have certain learning capabilities, intelligently correct false alarms and false alarms, and improve the accuracy of early warning.
  
2. intrusion activities can have a large time span and space Span
Premeditated intrusion activities often involve well-planned, tentative, and technical preparations, each step of an intrusion activity may be completed separately over a relatively long time span and a considerable space span, which brings difficulties to early warning. A detection model always has a limited time window to ignore certain facts that slide out of the time window. At the same time, the detection model has limited comprehensive association capabilities for abnormal phenomena in a large space.
  
3. No effective identification model is available for non-linear features.
The difficulty of the intrusion detection technology lies not only in the extraction of the intrusion mode, but also in the detection policies and algorithms of the intrusion mode. Because the intrusion mode is a static thing, and the actual intrusion activities are flexible and changeable. An effective intrusion detection model should be able to accept a large enough time span and space span. Technically speaking, the intrusion technology has developed to a certain stage, and the intrusion detection technology has not yet developed in theory, model, and practice. As can be seen in the market, all intrusion detection systems are at the same level. According to our analysis, Advanced Intrusion Detection Systems configured on important national networks should not be such a level of technology, or they are also seeking for other more effective detection methods.
In the face of complex network intrusion activities, the study of network early warning technology not only involves the research of intrusion technology, but also attaches more importance to the theoretical study of establishing intrusion detection policies and models.
  
   Iv. Main content of early warning research
The main contents of the network warning technology research include: network intrusion technology research, detection model research, audit analysis policy research, etc. By combining these technologies, we can form an organism of interactive development.
  
1. Research on intrusion technology
Intrusion technology research includes three parts:
First, keep a close track and analysis of the development of international intrusion technologies and continuously obtain the latest attack methods. By analyzing these known attack methods, the early warning system's detection capabilities are enriched.
Second, strengthen and use the audit, tracking and on-site recording functions of the early warning system to record and feedback abnormal event instances. Suspicious network activity features are extracted through instance analysis to expand the system's detection scope so that the system can respond to unknown intrusion activities.
Third, use the research results of attack technology to create new intrusion methods and apply them to detection technologies.
  
2. Research on Detection Models
For the early warning system, determining the detection model is the most important. Due to the complexity of intrusion activities, early warnings cannot be fully implemented only by understanding intrusion methods. Appropriate Detection Models should also be used in combination. In the research of Early Warning Technology, intrusion detection model is one of the key technologies.
  
Based on intrusion detection methods, intrusion detection models can be divided into network-based and system-based models. The network-based model monitors data streams on the network in real time to find activities with network attack characteristics. The system-based model analyzes the system's audit data to detect suspicious activities. These two models are complementary. The network-based model can objectively reflect network activities, especially the blind spots that can be monitored for system audits; the system-based model can more accurately monitor various activities in the system. Network-based models are restricted by the exchange network, while system-based models are not affected by the Exchange Network.
  
Based on intrusion detection policies, intrusion detection models can be divided into two types: abnormal features and normal features. The exception feature model is built on a known intrusion mode database, while the normal feature model is built on the normal operating mode of the system. The latter model involves two aspects: first, establishing normal behavior characteristics for the user and the system, and second, observing whether the actual system and user activity are different from the established normal behavior.
  
Likewise, these two models are complementary. The abnormal feature model can accurately detect known intrusion activities and has a low false alarm rate. For a definite application environment, the normal feature model has a precise normal system working mode, this allows you to discover all activities that deviate from the normal mode, including some unknown intrusion activities.
  
3. Audit Analysis Policy Research
Another focus of early warning technology research is the analysis and processing of audit data, including the identification of threat sources, determination of attempts, determination of hazard levels and capabilities. Audit data generated by early warnings is a valuable resource for detection and early warning. These audit data volumes may be large. In the absence of effective analysis methods, this resource will be wasted.
  
The information infrastructure of the 21st century is the Foundation Stage for various social activities. It is impossible to completely put an end to bad behaviors against information infrastructure within the foreseeable period. Strengthening management and necessary technical means are one of the ways to solve the problem.
  

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.