19.01.2014 Views

High-Performance Intrusion Detection with the Open-Source Bro NIDS

High-Performance Intrusion Detection with the Open-Source Bro NIDS

High-Performance Intrusion Detection with the Open-Source Bro NIDS

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Event Model<br />

Web<br />

Client<br />

1.2.3.4/4321<br />

...<br />

Stream of TCP packets<br />

Request for /index.html<br />

Status OK plus data<br />

SYN SYN ACK ACK ACK ACK FIN FIN<br />

...<br />

Web<br />

Server<br />

5.6.7.8/80<br />

Event<br />

connection_established(1.2.3.4/43215.6.7.8/80)<br />

TCP stream reassembly for originator<br />

Event<br />

http_request(1.2.3.4/43215.6.7.8/80, “GET”, “/index.html”)<br />

TCP stream reassembly for responder<br />

Event<br />

http_reply(1.2.3.4/43215.6.7.8/80, 200, “OK”, data)<br />

Event<br />

connection_finished(1.2.3.4/4321, 5.6.7.8/80)<br />

Guest Lecture, RWTH Aachen<br />

14<br />

Thursday, December 16, 2010

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!