JBriareos: A Secure and Scalable Distributed Intrusion Detection System

Mário Dinis da Silva e Barbosa · Open Repository of the University of Porto (University of Porto) · 2020

As networks increase size and complexity, there is a pressuring need to find suitable solutions for scalable intrusion detection that are able to uncover unknown attack vectors and share intelligence.While there are some available systems that cover partially our requirements, there does not seem to exist a unified architecture that provides all of these at once.We propose JBriareos, a Java-written, host-based intrusion detection and prevention system capable of analysing network traffic, that possesses an intelligence sharing network, and is an evolution of Briareos.Briareos [1] is a Python-written intrusion detection and prevention system capable of detecting unknown attack vectors.With Briareos, users are able to create their own detection and prevention modules and processing pipelines.It has inline, in which the network traffic is analysed locally, and distributed processing modes, which offloads the analysis to a distributed system, trading off being able to prevent an attack for performance on the host.Our goal in migrating Briareos to Java was to improve its packet analysis performance, as to lower resource usage on its host.Furthermore, we also completed the implementation of a manager server that provides a centralized way of managing configurations and propagate rules created by any instance of the system to every other instance running on the same administrative domain.Although we were not able to compare JBriareos with other more widespread solutions, as could not reproduce our modules on other systems, nor implement the main functionalities of other systems on our own, we: improved the system's performance when analysing captured packets (by about 85%, measuring a host's response times), as a result of the code's migration to Java; created a more structured approach to build new processing modules; implemented the previously mentioned manager server; and provided the distributed system with retroactive attack prevention capabilities, in addition to the already existing detection ones, by utilizing the manager server to propagate iptables rules created by the system's workers.

Read the paper · More papers on PaperTik