University of Notre Dame NetScale Laboratory

View   r34  >  r33  >  r32  >  r31  >  r30  ...
LockDown 34 - 23 Jul 2008 - Main.AaronStriegel
Line: 1 to 1
 
META TOPICPARENT name="Projects"

Lockdown: Simplifying Enterprise Network Management

Line: 12 to 12
 
  • Novel data mining / visualization: While visualization and exploration are the first steps, we intend to explore how to automate or guide the extraction of meaningful relationships, specifically drawing upon the rich work in social networking to assist with assessing the health of the network. Preliminary aspects include building modules into our visualization tool coupled with distributed execution on the grid of various machine learning algorithms (Chawla).
  • Creation of a streamlined framework for security management: Finally, the work will offer commentary on balancing expressiveness versus complexity to demonstrate minimal but effective security mechanisms. More importantly, the work will examine the tradeoffs of information gain for the monitoring of various properties not only with respect to security but also with respect to management and debugging (i.e. how much does characteristic X improve decision making versus characteristic Y).
Changed:
<
<

Visualization of Network Security Properties

>
>
The software toolkit is currently in development but available for download below. We are currently reworking the back end storage aspects and envision a mid-September release for the first official version of the software suite.

Visualization of Network Security Properties pdf

  Large Scale User View Complex systems are hard to understand and visualize. The causes for the problem are either due to the specific data is not available or inability to correlate and present the data in a meaningful and understandable way. Current logging scheme such as NetFlow data provides activity in terms of addresses and ports but are unable to tell what users and applications running on the management network. The identity of the traffic flow is important. Since the users and applications are the essential components of the network, the identity should be associated with the users and applications in addition to the hosts.
Line: 38 to 40
 

News

Jul 2008 Position Paper A presentation on Lockdown will be given at the Workshop on Usable IT Security Management by Andrew Blaich, a workshop at SOUPS (Symposium on Usable Privacy and Security).
Changed:
<
<
Dec 2007 Equipment Grant Professors Striegel and Thain have received a Sun Academic Excellence Grant (AEG) entitled "Unified SGD Support for Enterprise Network Management" for approximately $41k worth of equipment and software licenses. The purpose of the equipment will be to create a high-end database node / SunRay server for managing the Lockdown project which is focused on practical enterprise network security management as well as the creation of a new SunRay thin client pool. The new server offers exciting opportunities for the development of Lockdown in terms of application development from an Sun Global Desktop perspective (SunRay thin client) and trust dependency analysis of the SunRay itself from a management perspective. The equipment will enable the development of SGD-friendly tools for visualization of the Lockdown data (Java-based), optimizations focused on the CoolThreads? architecture (database), and direct support for SunRay security analyses into Lockdown itself.
>
>
Dec 2007 Equipment Grant Professors Striegel and Thain have received a Sun Academic Excellence Grant (AEG) entitled "Unified SGD Support for Enterprise Network Management" for approximately $41k worth of equipment and software licenses. The purpose of the equipment will be to create a high-end database node / SunRay server for managing the Lockdown project which is focused on practical enterprise network security management as well as the creation of a new SunRay thin client pool. The new server offers exciting opportunities for the development of Lockdown in terms of application development from an Sun Global Desktop perspective (SunRay thin client) and trust dependency analysis of the SunRay itself from a management perspective. The equipment will enable the development of SGD-friendly tools for visualization of the Lockdown data (Java-based), optimizations focused on the CoolThreads architecture (database), and direct support for SunRay security analyses into Lockdown itself.
 

Visible Output:

Changed:
<
<
  • Draft of submission to LISA 2008 - available upon request
>
>
  • C Q. Liao, A. Blaich, A. Striegel, Q. Liao, "ENAVis: Enterprise Network Activities Visualization," to appear at LISA (Large Installation System Administration) Conference, San Diego, CA, Nov. 2008.
 
  • Lockdown: Tech Report TR-2007-05*
  • Thesis Q. Liao, "Improving Network Insight Through Local Context Gathering and Analysis," Master Thesis, University of Notre Dame. Adviser: Dr. Aaron Striegel, Committee: Dr. Douglas Thain, Dr. Nitesh Chawla.
Changed:
<
<
>
>
  • Poster Andrew Blaich, Qi Liao, Brian Sullivan, Greg Allan, Aaron Striegel, Douglas Thain, "Lockdown: Distributed Policy Analysis and Enforcement within the Enterprise Network," poster at USENIX Security, August 2007. Writeup pdf
 

LockDown 33 - 11 Jun 2008 - Main.AaronStriegel
Line: 1 to 1
 
META TOPICPARENT name="Projects"
Changed:
<
<

Lockdown: Simplifying Enterprise Network Management with Local Context

>
>

Lockdown: Simplifying Enterprise Network Management

 
Changed:
<
<

Lockdown Overview:

>
>
Despite an ever increasing breadth of commercial and academic offerings into the field of security, the adoption of robust, fine granularity solutions by the enterprise has yet to occur on a significant threshold. While common lower end techniques such as virus scanners and firewalls have experienced near ubiquitous adoption, higher end solutions such as integrated endpoint security clients and others have seen only limited adoption with their adoption rates in fact shrinking in recent years. Given the choice between manageability at the cost of simplicity versus mechanism efficacy / richness of expressiveness at the cost of complexity, network administrators are choosing ease of management with insufficient resources as the primary driving factor.
 
Changed:
<
<
The administrator of an enterprise network has a responsibility to enforce the policies on the network. Yet, most security mechanisms do not map well to the intended policies. This has been due to the prevalence of simplistic tools that have poor enforcement but, yet are easy to manage. While advanced commercial solutions do exist that have stronger enforcement, they are significantly harder to manage. To that end, we propose Lockdown, a policy-oriented security approach that builds on the concept of local context to deliver a lighter weight approach to enterprise network security while striking a balance between the level of enforcement and level of management available to the network administrator. We describe how the Lockdown approach streamlines the process of network security management from network auditing to visualization to policy mapping to enforcement to validation. We demonstrate the strength of Lockdown through detailed assessments of an enterprise university network to show how local context significantly improves network management for the system administrator.
>
>
We posit that new research is needed that places the manageability of the system at the forefront rather than as an issue to be solved after the system is secure. We define manageability of a security approach in that security should streamline the entire security process, policy distribution, policy validation, policy auditing, and most importantly, debugging when systems or security components fail. Put simply, we posit that given the implicitly distributed nature of the network, security approaches that create unfriendly obstacles to debugging will always experience adoption difficulties. The goal of this research is to make significant strides with regards to management of the security process, specifically focusing on the three issues of management, visualization, and debugging. We focus on delivering an economy of expressiveness for enforcement mechanisms to contain complexity while coupling streamlined, pervasive monitoring to dramatically assist debugging.

The key outgrowths of the research will address the following areas:

  • Management as a first order property of system design: The work will develop a suite of software tools to visualize the security network and to explore the benefits and tradeoffs of prioritizing management over coverage with regards to resource impact and risk management. Secondary aspects include bringing experimental studies regarding tool efficacy / productivity improvements with expertise from our collaborators in business (D'Arcy), psychology (Crowell), and our Office of Information Technology Information Security effort (Chapple).
  • Novel data mining / visualization: While visualization and exploration are the first steps, we intend to explore how to automate or guide the extraction of meaningful relationships, specifically drawing upon the rich work in social networking to assist with assessing the health of the network. Preliminary aspects include building modules into our visualization tool coupled with distributed execution on the grid of various machine learning algorithms (Chawla).
  • Creation of a streamlined framework for security management: Finally, the work will offer commentary on balancing expressiveness versus complexity to demonstrate minimal but effective security mechanisms. More importantly, the work will examine the tradeoffs of information gain for the monitoring of various properties not only with respect to security but also with respect to management and debugging (i.e. how much does characteristic X improve decision making versus characteristic Y).

Visualization of Network Security Properties

Large Scale User View Complex systems are hard to understand and visualize. The causes for the problem are either due to the specific data is not available or inability to correlate and present the data in a meaningful and understandable way. Current logging scheme such as NetFlow data provides activity in terms of addresses and ports but are unable to tell what users and applications running on the management network. The identity of the traffic flow is important. Since the users and applications are the essential components of the network, the identity should be associated with the users and applications in addition to the hosts.

On the other hand, the administrator faces an overwhelming amount of data. Managing a large scale enterprise network is a tedious and cumbersome task. Several hundred to thousands of network connections are generated on a daily basis by each host. Tracking down precisely who and what is responsible for the generation of network connectivity is a non-trivial task. Requiring administrators to sift through endless giga-bytes of connection logs, or use a tool that offers no clear advantage other than data organization is not a valid solution. Administrators need a tool that allows them to sift through massive amounts of traffic logs in a visually appealing and interactive manner that encourages data exploration, rather than hinder it. Additionally, it is necessary for the why of a connection, i.e. the user and application levels of network activity, to be known rather than simply where it came from and went to.

Common solutions to this problem have involved tie-ins of network flow data and authentication systems such as Active Directory and Kerberos. Critically, the existing logging systems are not geared toward real-world system administration. Network flow data will only detail the where of a connection, where as an Active Directory and Kerberos tie-in can explain the who. A few visualization and data exploration tools that exist, primarily rely on chaining together network connections based on the flow data. However, multiple hop connections are typically obfuscated due to the nature of network flows and the level of detail supplied is traditionally limited to the IP addresses and port numbers involved.

Rather, a method to interactively explore the inter-relationships of the data so as to gain insight as to what is occurring as opposed to inferring, due to lack of log details or time to trace-back and locate the necessary information, is needed. For example, if an account on a network is compromised then it needs to be known what hosts that user account attempted to log into, along with the applications and programs they attempted to run, and files that may have been modified or touched. Knowing who (users) or what (applications), not inferring from IP and port, at both sides of connections is of particular interest in policy compliance auditing. Being able to present all of this information in a single visual that is appealing and manageable for an administrator would be a tremendous asset for network administration.

Screenshots

View - App Usage Application Policy Single User Exploration Meta Graph Visualization Control

Enforcement with Local Context

The administrator of an enterprise network has a responsibility to enforce the policies on the network. Yet, most security mechanisms do not map well to the intended policies. This has been due to the prevalence of simplistic tools that have poor enforcement but, yet are easy to manage. While advanced commercial solutions do exist that have stronger enforcement, they are significantly harder to manage. To that end, we propose Lockdown, a policy-oriented security approach that builds on the concept of local context to deliver a lighter weight approach to enterprise network security while striking a balance between the level of enforcement and level of management available to the network administrator.

We posit that the perspective at which enforcement and monitoring occurs needs to be shifted in such a way that the \emph{local context}, i.e. the why of a connection versus the where, forms the foundation of the security approach. By infusing enforcement with local context, high level policy can be followed more stringently as is seen in the Flash animation.

 
Deleted:
<
<
 

News

Added:
>
>
Jul 2008 Position Paper A presentation on Lockdown will be given at the Workshop on Usable IT Security Management by Andrew Blaich, a workshop at SOUPS (Symposium on Usable Privacy and Security).
 
Dec 2007 Equipment Grant Professors Striegel and Thain have received a Sun Academic Excellence Grant (AEG) entitled "Unified SGD Support for Enterprise Network Management" for approximately $41k worth of equipment and software licenses. The purpose of the equipment will be to create a high-end database node / SunRay server for managing the Lockdown project which is focused on practical enterprise network security management as well as the creation of a new SunRay thin client pool. The new server offers exciting opportunities for the development of Lockdown in terms of application development from an Sun Global Desktop perspective (SunRay thin client) and trust dependency analysis of the SunRay itself from a management perspective. The equipment will enable the development of SGD-friendly tools for visualization of the Lockdown data (Java-based), optimizations focused on the CoolThreads? architecture (database), and direct support for SunRay security analyses into Lockdown itself.

Visible Output:

Changed:
<
<
  • Lockdown: Tech Report TR-2007-05 and Submission to NSDI 2008 *
>
>
  • Draft of submission to LISA 2008 - available upon request
  • Lockdown: Tech Report TR-2007-05*
 
  • Thesis Q. Liao, "Improving Network Insight Through Local Context Gathering and Analysis," Master Thesis, University of Notre Dame. Adviser: Dr. Aaron Striegel, Committee: Dr. Douglas Thain, Dr. Nitesh Chawla.
  • USENIX Security '07 Poster: Presented by A. Blaich
  • Slides for CSE-SRS-2007 Poster Symposium.
Line: 27 to 56
 

Students:

Changed:
<
<
  • Andrew Blaich : graduate
  • Qi Liao : graduate
  • Brian Sullivan: undergrad
  • Greg Allan: undergrad
  • Ben Roesch: undergrad
>
>

Previous Students:

  • Tim Wright: graduate student - initial data gathering concept for risk management
  • Brian Sullivan: undergraduate student - PHP / web browsing of database
  • Greg Allan: undergraduate student - REU exploration of the usage of SONia for visualization
  • Ben Roesch: undergraduate student - Windows agent development
 

Related Work / Efforts

Line: 83 to 117
 
META FILEATTACHMENT attachment="Lockdown_OSX_Monitor.tar" attr="h" comment="" date="1192555669" name="Lockdown_OSX_Monitor.tar" path="Lockdown_OSX_Monitor.tar" size="686080" stream="Lockdown_OSX_Monitor.tar" user="Main.AndrewBlaich" version="1"
META FILEATTACHMENT attachment="Lockdown_Solaris_Monitor.tar" attr="h" comment="" date="1192556011" name="Lockdown_Solaris_Monitor.tar" path="Lockdown_Solaris_Monitor.tar" size="1085440" stream="Lockdown_Solaris_Monitor.tar" user="Main.AndrewBlaich" version="1"
META FILEATTACHMENT attachment="lockdown.pdf" attr="h" comment="" date="1196369244" name="lockdown.pdf" path="lockdown.pdf" size="973699" stream="lockdown.pdf" user="Main.AndrewBlaich" version="1"
Added:
>
>
META FILEATTACHMENT attachment="meta_graph.png" attr="" comment="HUA metagraph control" date="1213211771" name="meta_graph.png" path="meta_graph.png" size="53633" stream="meta_graph.png" tmpFilename="/usr/tmp/CGItemp47614" user="AaronStriegel" version="1"
META FILEATTACHMENT attachment="all_usr33_hop1.png" attr="" comment="User 33 connectivity view" date="1213211799" name="all_usr33_hop1.png" path="all_usr33_hop1.png" size="294939" stream="all_usr33_hop1.png" tmpFilename="/usr/tmp/CGItemp47675" user="AaronStriegel" version="1"
META FILEATTACHMENT attachment="usr-largeview.png" attr="" comment="All user view graph" date="1213211877" name="usr-largeview.png" path="usr-largeview.png" size="1865155" stream="usr-largeview.png" tmpFilename="/usr/tmp/CGItemp47702" user="AaronStriegel" version="1"
META FILEATTACHMENT attachment="case_clapton_app.png" attr="" comment="Example - clapton app usage" date="1213211947" name="case_clapton_app.png" path="case_clapton_app.png" size="614007" stream="case_clapton_app.png" tmpFilename="/usr/tmp/CGItemp47534" user="AaronStriegel" version="1"
META FILEATTACHMENT attachment="case-app-policy.png" attr="" comment="Example - app vs. policy" date="1213211999" name="case-app-policy.png" path="case-app-policy.png" size="181430" stream="case-app-policy.png" tmpFilename="/usr/tmp/CGItemp47801" user="AaronStriegel" version="1"

LockDown 32 - 07 Jan 2008 - Main.AaronStriegel
Line: 1 to 1
 
META TOPICPARENT name="Projects"

Lockdown: Simplifying Enterprise Network Management with Local Context

Line: 9 to 9
 
Added:
>
>

News

Dec 2007 Equipment Grant Professors Striegel and Thain have received a Sun Academic Excellence Grant (AEG) entitled "Unified SGD Support for Enterprise Network Management" for approximately $41k worth of equipment and software licenses. The purpose of the equipment will be to create a high-end database node / SunRay server for managing the Lockdown project which is focused on practical enterprise network security management as well as the creation of a new SunRay thin client pool. The new server offers exciting opportunities for the development of Lockdown in terms of application development from an Sun Global Desktop perspective (SunRay thin client) and trust dependency analysis of the SunRay itself from a management perspective. The equipment will enable the development of SGD-friendly tools for visualization of the Lockdown data (Java-based), optimizations focused on the CoolThreads? architecture (database), and direct support for SunRay security analyses into Lockdown itself.
 

Visible Output:

  • Lockdown: Tech Report TR-2007-05 and Submission to NSDI 2008 *
  • Thesis Q. Liao, "Improving Network Insight Through Local Context Gathering and Analysis," Master Thesis, University of Notre Dame. Adviser: Dr. Aaron Striegel, Committee: Dr. Douglas Thain, Dr. Nitesh Chawla.

LockDown 31 - 13 Dec 2007 - Main.AaronStriegel
Line: 1 to 1
 
META TOPICPARENT name="Projects"

Lockdown: Simplifying Enterprise Network Management with Local Context

Line: 29 to 29
 
  • Ben Roesch: undergrad

Related Work / Efforts

Added:
>
>
 

LockDown 30 - 29 Nov 2007 - Main.AndrewBlaich
Line: 1 to 1
 
META TOPICPARENT name="Projects"
Changed:
<
<

Lockdown

Faculty: Dr. Aaron Striegel, Dr. Douglas Thain

Students: Andrew Blaich, Qi Liao, Brian Sullivan, Greg Allan, Ben Roesch

>
>

Lockdown: Simplifying Enterprise Network Management with Local Context

 

Lockdown Overview:

The administrator of an enterprise network has a responsibility to enforce the policies on the network. Yet, most security mechanisms do not map well to the intended policies. This has been due to the prevalence of simplistic tools that have poor enforcement but, yet are easy to manage. While advanced commercial solutions do exist that have stronger enforcement, they are significantly harder to manage. To that end, we propose Lockdown, a policy-oriented security approach that builds on the concept of local context to deliver a lighter weight approach to enterprise network security while striking a balance between the level of enforcement and level of management available to the network administrator. We describe how the Lockdown approach streamlines the process of network security management from network auditing to visualization to policy mapping to enforcement to validation. We demonstrate the strength of Lockdown through detailed assessments of an enterprise university network to show how local context significantly improves network management for the system administrator.

Deleted:
<
<
Read about the LockdownStructure.
 
Changed:
<
<

Lockdown

  • LSM Enforcement
  • Monitor data gathering

Publications:

>
>

Visible Output:

  • Lockdown: Tech Report TR-2007-05 and Submission to NSDI 2008 *
 
  • Thesis Q. Liao, "Improving Network Insight Through Local Context Gathering and Analysis," Master Thesis, University of Notre Dame. Adviser: Dr. Aaron Striegel, Committee: Dr. Douglas Thain, Dr. Nitesh Chawla.
  • USENIX Security '07 Poster: Presented by A. Blaich
  • Slides for CSE-SRS-2007 Poster Symposium.
Added:
>
>
 
Changed:
<
<

Source Code

NOTE: all code is in constant development, newer versions will be posted as they are made available, use at your own risk!

  • Monitor: The Monitor is installed on each host within the network and is responsible for collecting the local context [netstat, ps, and lsof data] and sending it to the collecting server.

  • Enforcer: The Enforcer is a Linux Security Module, LSM, that is responsible for enforcing policy within the kernel.
    • Linux [2.6 kernel]: update coming soon
>
>

People Involved

Faculty:

Students:

  • Andrew Blaich : graduate
  • Qi Liao : graduate
  • Brian Sullivan: undergrad
  • Greg Allan: undergrad
  • Ben Roesch: undergrad
 
Changed:
<
<
  • Repository: The server processes data uploaded by the Monitors and manages the database (SQL) for storing the information. It contains analysis functions for extracting data patterns from the database.
>
>

Related Work / Efforts

 

Line: 85 to 76
 
META FILEATTACHMENT attachment="recycle_ld_invert.swf" attr="h" comment="" date="1192553678" name="recycle_ld_invert.swf" path="recycle_ld_invert.swf" size="30313" stream="recycle_ld_invert.swf" user="Main.AndrewBlaich" version="1"
META FILEATTACHMENT attachment="Lockdown_OSX_Monitor.tar" attr="h" comment="" date="1192555669" name="Lockdown_OSX_Monitor.tar" path="Lockdown_OSX_Monitor.tar" size="686080" stream="Lockdown_OSX_Monitor.tar" user="Main.AndrewBlaich" version="1"
META FILEATTACHMENT attachment="Lockdown_Solaris_Monitor.tar" attr="h" comment="" date="1192556011" name="Lockdown_Solaris_Monitor.tar" path="Lockdown_Solaris_Monitor.tar" size="1085440" stream="Lockdown_Solaris_Monitor.tar" user="Main.AndrewBlaich" version="1"
Added:
>
>
META FILEATTACHMENT attachment="lockdown.pdf" attr="h" comment="" date="1196369244" name="lockdown.pdf" path="lockdown.pdf" size="973699" stream="lockdown.pdf" user="Main.AndrewBlaich" version="1"

LockDown 29 - 29 Nov 2007 - Main.AndrewBlaich
Line: 1 to 1
 
META TOPICPARENT name="Projects"

Lockdown

Line: 43 to 43
 
Changed:
<
<
META FILEATTACHMENT attachment="Top_uid-all.png" attr="" comment="Top USERs making most connections" date="1186502994" name="Top_uid-all.png" path="C:\temp\Top_uid-all.png" size="12893" stream="C:\temp\Top_uid-all.png" user="Main.QiLiao" version="1"
META FILEATTACHMENT attachment="Top_program_full-all.png" attr="" comment="Top PROGRAMs making most connections" date="1186503051" name="Top_program_full-all.png" path="C:\temp\Top_program_full-all.png" size="20053" stream="C:\temp\Top_program_full-all.png" user="Main.QiLiao" version="1"
META FILEATTACHMENT attachment="Top_host-all.png" attr="" comment="Top HOSTs making most connections" date="1186503097" name="Top_host-all.png" path="C:\temp\Top_host-all.png" size="11356" stream="C:\temp\Top_host-all.png" user="Main.QiLiao" version="1"
META FILEATTACHMENT attachment="Top_gid-all.png" attr="" comment="Top GROUPs making most connections" date="1186503124" name="Top_gid-all.png" path="C:\temp\Top_gid-all.png" size="10531" stream="C:\temp\Top_gid-all.png" user="Main.QiLiao" version="1"
META FILEATTACHMENT attachment="Top_local_port-all.png" attr="" comment="Top LOCAL PORTs making most connections" date="1186503152" name="Top_local_port-all.png" path="C:\temp\Top_local_port-all.png" size="12935" stream="C:\temp\Top_local_port-all.png" user="Main.QiLiao" version="1"
META FILEATTACHMENT attachment="Top_foreign_port-all.png" attr="" comment="Top FOREIGN PORTs with most connections" date="1186503201" name="Top_foreign_port-all.png" path="C:\temp\Top_foreign_port-all.png" size="12424" stream="C:\temp\Top_foreign_port-all.png" user="Main.QiLiao" version="1"
META FILEATTACHMENT attachment="Top_foreign_ip-all.png" attr="" comment="Top FOREIGN HOSTs with most connections" date="1186503229" name="Top_foreign_ip-all.png" path="C:\temp\Top_foreign_ip-all.png" size="15699" stream="C:\temp\Top_foreign_ip-all.png" user="Main.QiLiao" version="1"
META FILEATTACHMENT attachment="InstNumOfConn-all.png" attr="" comment="Number of Connections (all hosts)" date="1186503272" name="InstNumOfConn-all.png" path="C:\temp\InstNumOfConn-all.png" size="17908" stream="C:\temp\InstNumOfConn-all.png" user="Main.QiLiao" version="1"
META FILEATTACHMENT attachment="InstNumOfConn-loco13.png" attr="" comment="Number of Connections (loco13)" date="1186503300" name="InstNumOfConn-loco13.png" path="C:\temp\InstNumOfConn-loco13.png" size="13704" stream="C:\temp\InstNumOfConn-loco13.png" user="Main.QiLiao" version="1"
META FILEATTACHMENT attachment="InstNumOfConn-wombat00.png" attr="" comment="Number of Connections (wombat00)" date="1186503325" name="InstNumOfConn-wombat00.png" path="C:\temp\InstNumOfConn-wombat00.png" size="16433" stream="C:\temp\InstNumOfConn-wombat00.png" user="Main.QiLiao" version="1"
META FILEATTACHMENT attachment="InstNumOfConn-wombat01.png" attr="" comment="Number of Connections (wombat01)" date="1186503343" name="InstNumOfConn-wombat01.png" path="C:\temp\InstNumOfConn-wombat01.png" size="16787" stream="C:\temp\InstNumOfConn-wombat01.png" user="Main.QiLiao" version="1"
META FILEATTACHMENT attachment="InstNumOfConn-wombat04.png" attr="" comment="Number of Connections (wombat04)" date="1186503364" name="InstNumOfConn-wombat04.png" path="C:\temp\InstNumOfConn-wombat04.png" size="12848" stream="C:\temp\InstNumOfConn-wombat04.png" user="Main.QiLiao" version="1"
META FILEATTACHMENT attachment="TOP_uid_foreign_ips_7_12_2007--7_13_2007.png" attr="" comment="Top USERs contacting most distinct hosts (day 1)" date="1186503434" name="TOP_uid_foreign_ips_7_12_2007--7_13_2007.png" path="C:\temp\TOP_uid_foreign_ips_7_12_2007--7_13_2007.png" size="13749" stream="C:\temp\TOP_uid_foreign_ips_7_12_2007--7_13_2007.png" user="Main.QiLiao" version="1"
META FILEATTACHMENT attachment="TOP_uid_foreign_ips_7_13_2007--7_14_2007.png" attr="" comment="Top USERs contacting most distinct hosts (day 2)" date="1186503461" name="TOP_uid_foreign_ips_7_13_2007--7_14_2007.png" path="C:\temp\TOP_uid_foreign_ips_7_13_2007--7_14_2007.png" size="15803" stream="C:\temp\TOP_uid_foreign_ips_7_13_2007--7_14_2007.png" user="Main.QiLiao" version="1"
META FILEATTACHMENT attachment="TOP_uid_local_apps_7_12_2007--7_13_2007.png" attr="" comment="Top USERs connecting with most distinct applications (day 1)" date="1186503500" name="TOP_uid_local_apps_7_12_2007--7_13_2007.png" path="C:\temp\TOP_uid_local_apps_7_12_2007--7_13_2007.png" size="15924" stream="C:\temp\TOP_uid_local_apps_7_12_2007--7_13_2007.png" user="Main.QiLiao" version="1"
META FILEATTACHMENT attachment="TOP_uid_local_apps_7_13_2007--7_14_2007.png" attr="" comment="Top USERs connecting with most distinct applications (day 2)" date="1186503527" name="TOP_uid_local_apps_7_13_2007--7_14_2007.png" path="C:\temp\TOP_uid_local_apps_7_13_2007--7_14_2007.png" size="17048" stream="C:\temp\TOP_uid_local_apps_7_13_2007--7_14_2007.png" user="Main.QiLiao" version="1"
META FILEATTACHMENT attachment="FileSizes.png" attr="" comment="Avergae size of data files uploaded by agents" date="1186503576" name="FileSizes.png" path="C:\temp\FileSizes.png" size="17466" stream="C:\temp\FileSizes.png" user="Main.QiLiao" version="1"
META FILEATTACHMENT attachment="localport_uid_app.bmp" attr="" comment="2D plot of LOCAL_PORT and UID (class=APPLICATION)" date="1186503659" name="localport_uid_app.bmp" path="C:\temp\localport_uid_app.bmp" size="3793602" stream="C:\temp\localport_uid_app.bmp" user="Main.QiLiao" version="1"
META FILEATTACHMENT attachment="foreignport_uid_app.bmp" attr="" comment="2D plot of FOREIGN_PORT and UID (class=APPLICATION)" date="1186503704" name="foreignport_uid_app.bmp" path="C:\temp\foreignport_uid_app.bmp" size="3801530" stream="C:\temp\foreignport_uid_app.bmp" user="Main.QiLiao" version="1"
META FILEATTACHMENT attachment="localport_app_usr.bmp" attr="" comment="2D plot of LOCAL_PORT and APPLICATION (class=UID)" date="1186503752" name="localport_app_usr.bmp" path="C:\temp\localport_app_usr.bmp" size="3786070" stream="C:\temp\localport_app_usr.bmp" user="Main.QiLiao" version="1"
META FILEATTACHMENT attachment="foreignport_app_usr.bmp" attr="" comment="2D plot of FOREIGN_PORT and APPLICATION (class=UID)" date="1186503788" name="foreignport_app_usr.bmp" path="C:\temp\foreignport_app_usr.bmp" size="3801258" stream="C:\temp\foreignport_app_usr.bmp" user="Main.QiLiao" version="1"
META FILEATTACHMENT attachment="dist_all_fields_5_1--5_3_2007.bmp" attr="" comment="Distribution of all fields in 2 days" date="1186503865" name="dist_all_fields_5_1--5_3_2007.bmp" path="C:\temp\dist_all_fields_5_1--5_3_2007.bmp" size="3686354" stream="C:\temp\dist_all_fields_5_1--5_3_2007.bmp" user="Main.QiLiao" version="1"
META FILEATTACHMENT attachment="dist_all_fields_app_5_1--5_3_2007.png" attr="" comment="Distribution of all fields in 2 days (class=APPLICATION)" date="1186503900" name="dist_all_fields_app_5_1--5_3_2007.png" path="C:\temp\dist_all_fields_app_5_1--5_3_2007.png" size="50658" stream="C:\temp\dist_all_fields_app_5_1--5_3_2007.png" user="Main.QiLiao" version="1"
META FILEATTACHMENT attachment="dist_all_fields_uid_5_1--5_3_2007.png" attr="" comment="Distribution of all fields in 2 days (class=USER)" date="1186503927" name="dist_all_fields_uid_5_1--5_3_2007.png" path="C:\temp\dist_all_fields_uid_5_1--5_3_2007.png" size="48309" stream="C:\temp\dist_all_fields_uid_5_1--5_3_2007.png" user="Main.QiLiao" version="1"
META FILEATTACHMENT attachment="dist_localport_1000_count_app.png" attr="" comment="LOCAL_PORT distribution in terms of APPLICATIONs" date="1186503983" name="dist_localport_1000_count_app.png" path="C:\temp\dist_localport_1000_count_app.png" size="17218" stream="C:\temp\dist_localport_1000_count_app.png" user="Main.QiLiao" version="1"
META FILEATTACHMENT attachment="dist_foreignport_1000_count_app.png" attr="" comment="FOREIGN_PORT distribution in terms of APPLICATIONs" date="1186504033" name="dist_foreignport_1000_count_app.png" path="C:\temp\dist_foreignport_1000_count_app.png" size="16625" stream="C:\temp\dist_foreignport_1000_count_app.png" user="Main.QiLiao" version="1"
META FILEATTACHMENT attachment="dist_localport_1_count_app_select.txt" attr="" comment="Selected LOCAL PORT on which different applications used" date="1186504450" name="dist_localport_1_count_app_select.txt" path="C:\LQ\ND\Thesis\Paper\thesis\fig\backup\txt\dist_localport_1_count_app_select.txt" size="1384" stream="C:\LQ\ND\Thesis\Paper\thesis\fig\backup\txt\dist_localport_1_count_app_select.txt" user="Main.QiLiao" version="1"
META FILEATTACHMENT attachment="dist_foreignport_1_count_app_select.txt" attr="" comment="Selected FOREIGN PORT on which different applications used" date="1186504484" name="dist_foreignport_1_count_app_select.txt" path="C:\LQ\ND\Thesis\Paper\thesis\fig\backup\txt\dist_foreignport_1_count_app_select.txt" size="6059" stream="C:\LQ\ND\Thesis\Paper\thesis\fig\backup\txt\dist_foreignport_1_count_app_select.txt" user="Main.QiLiao" version="1"
META FILEATTACHMENT attachment="exp_deploy.zip" attr="" comment="Lockdown agent code" date="1186506862" name="exp_deploy.zip" path="exp_deploy.zip" size="10845" stream="exp_deploy.zip" user="Main.AndrewBlaich" version="1"
META FILEATTACHMENT attachment="expsicor_server.zip" attr="" comment="Database server processing code" date="1186521247" name="expsicor_server.zip" path="C:\temp\expsicor_server.zip" size="70875" stream="C:\temp\expsicor_server.zip" user="Main.QiLiao" version="1"
META FILEATTACHMENT attachment="host-chain.png" attr="" comment="Host Chaining" date="1186521633" name="host-chain.png" path="C:\LQ\ND\Thesis\Paper\thesis\fig\backup\picture\host-chain.png" size="54367" stream="C:\LQ\ND\Thesis\Paper\thesis\fig\backup\picture\host-chain.png" user="Main.QiLiao" version="1"
META FILEATTACHMENT attachment="usr-chain.png" attr="" comment="User Chaining" date="1186521656" name="usr-chain.png" path="C:\LQ\ND\Thesis\Paper\thesis\fig\backup\picture\usr-chain.png" size="67738" stream="C:\LQ\ND\Thesis\Paper\thesis\fig\backup\picture\usr-chain.png" user="Main.QiLiao" version="1"
META FILEATTACHMENT attachment="app-chain.png" attr="" comment="Application Chaining" date="1186521679" name="app-chain.png" path="C:\LQ\ND\Thesis\Paper\thesis\fig\backup\picture\app-chain.png" size="60576" stream="C:\LQ\ND\Thesis\Paper\thesis\fig\backup\picture\app-chain.png" user="Main.QiLiao" version="1"
META FILEATTACHMENT attachment="data_format_tools.png" attr="" comment="Intermediate format of data collected by tools (netstat, ps, lsof)" date="1186522772" name="data_format_tools.png" path="C:\LQ\ND\Thesis\Paper\thesis\fig\backup\picture\data_format_tools.png" size="8773" stream="C:\LQ\ND\Thesis\Paper\thesis\fig\backup\picture\data_format_tools.png" user="Main.QiLiao" version="1"
META FILEATTACHMENT attachment="QueryBrowser.png" attr="" comment="Screenshot of Query Browser" date="1186590524" name="QueryBrowser.png" path="QueryBrowser.png" size="338440" stream="QueryBrowser.png" user="Main.BrianSullivan" version="2"
META FILEATTACHMENT attachment="BarGraph.png" attr="" comment="Screenshot of Bar Graph" date="1186590756" name="BarGraph.png" path="BarGraph.png" size="174953" stream="BarGraph.png" user="Main.BrianSullivan" version="1"
META FILEATTACHMENT attachment="Agent-Architecture.png" attr="" comment="Agent architecture" date="1186601087" name="Agent-Architecture.png" path="Agent-Architecture.png" size="66668" stream="Agent-Architecture.png" user="Main.AaronStriegel" version="1"
META FILEATTACHMENT attachment="lockdown_agent_setup.msi" attr="" comment="Windows Service MSI Installer" date="1192056957" name="lockdown_agent_setup.msi" path="lockdown_agent_setup.msi" size="381952" stream="lockdown_agent_setup.msi" user="Main.BenRoesch" version="1"
>
>
META FILEATTACHMENT attachment="Top_uid-all.png" attr="h" comment="Top USERs making most connections" date="1186502994" name="Top_uid-all.png" path="C:\temp\Top_uid-all.png" size="12893" stream="C:\temp\Top_uid-all.png" user="Main.QiLiao" version="1"
META FILEATTACHMENT attachment="Top_program_full-all.png" attr="h" comment="Top PROGRAMs making most connections" date="1186503051" name="Top_program_full-all.png" path="C:\temp\Top_program_full-all.png" size="20053" stream="C:\temp\Top_program_full-all.png" user="Main.QiLiao" version="1"
META FILEATTACHMENT attachment="Top_host-all.png" attr="h" comment="Top HOSTs making most connections" date="1186503097" name="Top_host-all.png" path="C:\temp\Top_host-all.png" size="11356" stream="C:\temp\Top_host-all.png" user="Main.QiLiao" version="1"
META FILEATTACHMENT attachment="Top_gid-all.png" attr="h" comment="Top GROUPs making most connections" date="1186503124" name="Top_gid-all.png" path="C:\temp\Top_gid-all.png" size="10531" stream="C:\temp\Top_gid-all.png" user="Main.QiLiao" version="1"
META FILEATTACHMENT attachment="Top_local_port-all.png" attr="h" comment="Top LOCAL PORTs making most connections" date="1186503152" name="Top_local_port-all.png" path="C:\temp\Top_local_port-all.png" size="12935" stream="C:\temp\Top_local_port-all.png" user="Main.QiLiao" version="1"
META FILEATTACHMENT attachment="Top_foreign_port-all.png" attr="h" comment="Top FOREIGN PORTs with most connections" date="1186503201" name="Top_foreign_port-all.png" path="C:\temp\Top_foreign_port-all.png" size="12424" stream="C:\temp\Top_foreign_port-all.png" user="Main.QiLiao" version="1"
META FILEATTACHMENT attachment="Top_foreign_ip-all.png" attr="h" comment="Top FOREIGN HOSTs with most connections" date="1186503229" name="Top_foreign_ip-all.png" path="C:\temp\Top_foreign_ip-all.png" size="15699" stream="C:\temp\Top_foreign_ip-all.png" user="Main.QiLiao" version="1"
META FILEATTACHMENT attachment="InstNumOfConn-all.png" attr="h" comment="Number of Connections (all hosts)" date="1186503272" name="InstNumOfConn-all.png" path="C:\temp\InstNumOfConn-all.png" size="17908" stream="C:\temp\InstNumOfConn-all.png" user="Main.QiLiao" version="1"
META FILEATTACHMENT attachment="InstNumOfConn-loco13.png" attr="h" comment="Number of Connections (loco13)" date="1186503300" name="InstNumOfConn-loco13.png" path="C:\temp\InstNumOfConn-loco13.png" size="13704" stream="C:\temp\InstNumOfConn-loco13.png" user="Main.QiLiao" version="1"
META FILEATTACHMENT attachment="InstNumOfConn-wombat00.png" attr="h" comment="Number of Connections (wombat00)" date="1186503325" name="InstNumOfConn-wombat00.png" path="C:\temp\InstNumOfConn-wombat00.png" size="16433" stream="C:\temp\InstNumOfConn-wombat00.png" user="Main.QiLiao" version="1"
META FILEATTACHMENT attachment="InstNumOfConn-wombat01.png" attr="h" comment="Number of Connections (wombat01)" date="1186503343" name="InstNumOfConn-wombat01.png" path="C:\temp\InstNumOfConn-wombat01.png" size="16787" stream="C:\temp\InstNumOfConn-wombat01.png" user="Main.QiLiao" version="1"
META FILEATTACHMENT attachment="InstNumOfConn-wombat04.png" attr="h" comment="Number of Connections (wombat04)" date="1186503364" name="InstNumOfConn-wombat04.png" path="C:\temp\InstNumOfConn-wombat04.png" size="12848" stream="C:\temp\InstNumOfConn-wombat04.png" user="Main.QiLiao" version="1"
META FILEATTACHMENT attachment="TOP_uid_foreign_ips_7_12_2007--7_13_2007.png" attr="h" comment="Top USERs contacting most distinct hosts (day 1)" date="1186503434" name="TOP_uid_foreign_ips_7_12_2007--7_13_2007.png" path="C:\temp\TOP_uid_foreign_ips_7_12_2007--7_13_2007.png" size="13749" stream="C:\temp\TOP_uid_foreign_ips_7_12_2007--7_13_2007.png" user="Main.QiLiao" version="1"
META FILEATTACHMENT attachment="TOP_uid_foreign_ips_7_13_2007--7_14_2007.png" attr="h" comment="Top USERs contacting most distinct hosts (day 2)" date="1186503461" name="TOP_uid_foreign_ips_7_13_2007--7_14_2007.png" path="C:\temp\TOP_uid_foreign_ips_7_13_2007--7_14_2007.png" size="15803" stream="C:\temp\TOP_uid_foreign_ips_7_13_2007--7_14_2007.png" user="Main.QiLiao" version="1"
META FILEATTACHMENT attachment="TOP_uid_local_apps_7_12_2007--7_13_2007.png" attr="h" comment="Top USERs connecting with most distinct applications (day 1)" date="1186503500" name="TOP_uid_local_apps_7_12_2007--7_13_2007.png" path="C:\temp\TOP_uid_local_apps_7_12_2007--7_13_2007.png" size="15924" stream="C:\temp\TOP_uid_local_apps_7_12_2007--7_13_2007.png" user="Main.QiLiao" version="1"
META FILEATTACHMENT attachment="TOP_uid_local_apps_7_13_2007--7_14_2007.png" attr="h" comment="Top USERs connecting with most distinct applications (day 2)" date="1186503527" name="TOP_uid_local_apps_7_13_2007--7_14_2007.png" path="C:\temp\TOP_uid_local_apps_7_13_2007--7_14_2007.png" size="17048" stream="C:\temp\TOP_uid_local_apps_7_13_2007--7_14_2007.png" user="Main.QiLiao" version="1"
META FILEATTACHMENT attachment="FileSizes.png" attr="h" comment="Avergae size of data files uploaded by agents" date="1186503576" name="FileSizes.png" path="C:\temp\FileSizes.png" size="17466" stream="C:\temp\FileSizes.png" user="Main.QiLiao" version="1"
META FILEATTACHMENT attachment="localport_uid_app.bmp" attr="h" comment="2D plot of LOCAL_PORT and UID (class=APPLICATION)" date="1186503659" name="localport_uid_app.bmp" path="C:\temp\localport_uid_app.bmp" size="3793602" stream="C:\temp\localport_uid_app.bmp" user="Main.QiLiao" version="1"
META FILEATTACHMENT attachment="foreignport_uid_app.bmp" attr="h" comment="2D plot of FOREIGN_PORT and UID (class=APPLICATION)" date="1186503704" name="foreignport_uid_app.bmp" path="C:\temp\foreignport_uid_app.bmp" size="3801530" stream="C:\temp\foreignport_uid_app.bmp" user="Main.QiLiao" version="1"
META FILEATTACHMENT attachment="localport_app_usr.bmp" attr="h" comment="2D plot of LOCAL_PORT and APPLICATION (class=UID)" date="1186503752" name="localport_app_usr.bmp" path="C:\temp\localport_app_usr.bmp" size="3786070" stream="C:\temp\localport_app_usr.bmp" user="Main.QiLiao" version="1"
META FILEATTACHMENT attachment="foreignport_app_usr.bmp" attr="h" comment="2D plot of FOREIGN_PORT and APPLICATION (class=UID)" date="1186503788" name="foreignport_app_usr.bmp" path="C:\temp\foreignport_app_usr.bmp" size="3801258" stream="C:\temp\foreignport_app_usr.bmp" user="Main.QiLiao" version="1"
META FILEATTACHMENT attachment="dist_all_fields_5_1--5_3_2007.bmp" attr="h" comment="Distribution of all fields in 2 days" date="1186503865" name="dist_all_fields_5_1--5_3_2007.bmp" path="C:\temp\dist_all_fields_5_1--5_3_2007.bmp" size="3686354" stream="C:\temp\dist_all_fields_5_1--5_3_2007.bmp" user="Main.QiLiao" version="1"
META FILEATTACHMENT attachment="dist_all_fields_app_5_1--5_3_2007.png" attr="h" comment="Distribution of all fields in 2 days (class=APPLICATION)" date="1186503900" name="dist_all_fields_app_5_1--5_3_2007.png" path="C:\temp\dist_all_fields_app_5_1--5_3_2007.png" size="50658" stream="C:\temp\dist_all_fields_app_5_1--5_3_2007.png" user="Main.QiLiao" version="1"
META FILEATTACHMENT attachment="dist_all_fields_uid_5_1--5_3_2007.png" attr="h" comment="Distribution of all fields in 2 days (class=USER)" date="1186503927" name="dist_all_fields_uid_5_1--5_3_2007.png" path="C:\temp\dist_all_fields_uid_5_1--5_3_2007.png" size="48309" stream="C:\temp\dist_all_fields_uid_5_1--5_3_2007.png" user="Main.QiLiao" version="1"
META FILEATTACHMENT attachment="dist_localport_1000_count_app.png" attr="h" comment="LOCAL_PORT distribution in terms of APPLICATIONs" date="1186503983" name="dist_localport_1000_count_app.png" path="C:\temp\dist_localport_1000_count_app.png" size="17218" stream="C:\temp\dist_localport_1000_count_app.png" user="Main.QiLiao" version="1"
META FILEATTACHMENT attachment="dist_foreignport_1000_count_app.png" attr="h" comment="FOREIGN_PORT distribution in terms of APPLICATIONs" date="1186504033" name="dist_foreignport_1000_count_app.png" path="C:\temp\dist_foreignport_1000_count_app.png" size="16625" stream="C:\temp\dist_foreignport_1000_count_app.png" user="Main.QiLiao" version="1"
META FILEATTACHMENT attachment="dist_localport_1_count_app_select.txt" attr="h" comment="Selected LOCAL PORT on which different applications used" date="1186504450" name="dist_localport_1_count_app_select.txt" path="C:\LQ\ND\Thesis\Paper\thesis\fig\backup\txt\dist_localport_1_count_app_select.txt" size="1384" stream="C:\LQ\ND\Thesis\Paper\thesis\fig\backup\txt\dist_localport_1_count_app_select.txt" user="Main.QiLiao" version="1"
META FILEATTACHMENT attachment="dist_foreignport_1_count_app_select.txt" attr="h" comment="Selected FOREIGN PORT on which different applications used" date="1186504484" name="dist_foreignport_1_count_app_select.txt" path="C:\LQ\ND\Thesis\Paper\thesis\fig\backup\txt\dist_foreignport_1_count_app_select.txt" size="6059" stream="C:\LQ\ND\Thesis\Paper\thesis\fig\backup\txt\dist_foreignport_1_count_app_select.txt" user="Main.QiLiao" version="1"
META FILEATTACHMENT attachment="exp_deploy.zip" attr="h" comment="Lockdown agent code" date="1186506862" name="exp_deploy.zip" path="exp_deploy.zip" size="10845" stream="exp_deploy.zip" user="Main.AndrewBlaich" version="1"
META FILEATTACHMENT attachment="expsicor_server.zip" attr="h" comment="Database server processing code" date="1186521247" name="expsicor_server.zip" path="C:\temp\expsicor_server.zip" size="70875" stream="C:\temp\expsicor_server.zip" user="Main.QiLiao" version="1"
META FILEATTACHMENT attachment="host-chain.png" attr="h" comment="Host Chaining" date="1186521633" name="host-chain.png" path="C:\LQ\ND\Thesis\Paper\thesis\fig\backup\picture\host-chain.png" size="54367" stream="C:\LQ\ND\Thesis\Paper\thesis\fig\backup\picture\host-chain.png" user="Main.QiLiao" version="1"
META FILEATTACHMENT attachment="usr-chain.png" attr="h" comment="User Chaining" date="1186521656" name="usr-chain.png" path="C:\LQ\ND\Thesis\Paper\thesis\fig\backup\picture\usr-chain.png" size="67738" stream="C:\LQ\ND\Thesis\Paper\thesis\fig\backup\picture\usr-chain.png" user="Main.QiLiao" version="1"
META FILEATTACHMENT attachment="app-chain.png" attr="h" comment="Application Chaining" date="1186521679" name="app-chain.png" path="C:\LQ\ND\Thesis\Paper\thesis\fig\backup\picture\app-chain.png" size="60576" stream="C:\LQ\ND\Thesis\Paper\thesis\fig\backup\picture\app-chain.png" user="Main.QiLiao" version="1"
META FILEATTACHMENT attachment="data_format_tools.png" attr="h" comment="Intermediate format of data collected by tools (netstat, ps, lsof)" date="1186522772" name="data_format_tools.png" path="C:\LQ\ND\Thesis\Paper\thesis\fig\backup\picture\data_format_tools.png" size="8773" stream="C:\LQ\ND\Thesis\Paper\thesis\fig\backup\picture\data_format_tools.png" user="Main.QiLiao" version="1"
META FILEATTACHMENT attachment="QueryBrowser.png" attr="h" comment="Screenshot of Query Browser" date="1186590524" name="QueryBrowser.png" path="QueryBrowser.png" size="338440" stream="QueryBrowser.png" user="Main.BrianSullivan" version="2"
META FILEATTACHMENT attachment="BarGraph.png" attr="h" comment="Screenshot of Bar Graph" date="1186590756" name="BarGraph.png" path="BarGraph.png" size="174953" stream="BarGraph.png" user="Main.BrianSullivan" version="1"
META FILEATTACHMENT attachment="Agent-Architecture.png" attr="h" comment="Agent architecture" date="1186601087" name="Agent-Architecture.png" path="Agent-Architecture.png" size="66668" stream="Agent-Architecture.png" user="Main.AaronStriegel" version="1"
META FILEATTACHMENT attachment="lockdown_agent_setup.msi" attr="h" comment="Windows Service MSI Installer" date="1192056957" name="lockdown_agent_setup.msi" path="lockdown_agent_setup.msi" size="381952" stream="lockdown_agent_setup.msi" user="Main.BenRoesch" version="1"
 
META FILEATTACHMENT attachment="recycle_ld.swf" attr="h" comment="" date="1192463961" name="recycle_ld.swf" path="recycle_ld.swf" size="5870" stream="recycle_ld.swf" user="Main.AndrewBlaich" version="1"
META FILEATTACHMENT attachment="recycle_ld_invert.swf" attr="h" comment="" date="1192553678" name="recycle_ld_invert.swf" path="recycle_ld_invert.swf" size="30313" stream="recycle_ld_invert.swf" user="Main.AndrewBlaich" version="1"
META FILEATTACHMENT attachment="Lockdown_OSX_Monitor.tar" attr="h" comment="" date="1192555669" name="Lockdown_OSX_Monitor.tar" path="Lockdown_OSX_Monitor.tar" size="686080" stream="Lockdown_OSX_Monitor.tar" user="Main.AndrewBlaich" version="1"
Changed:
<
<
META FILEATTACHMENT attachment="Lockdown_Solaris_Monitor.tar" attr="" comment="" date="1192556011" name="Lockdown_Solaris_Monitor.tar" path="Lockdown_Solaris_Monitor.tar" size="1085440" stream="Lockdown_Solaris_Monitor.tar" user="Main.AndrewBlaich" version="1"
>
>
META FILEATTACHMENT attachment="Lockdown_Solaris_Monitor.tar" attr="h" comment="" date="1192556011" name="Lockdown_Solaris_Monitor.tar" path="Lockdown_Solaris_Monitor.tar" size="1085440" stream="Lockdown_Solaris_Monitor.tar" user="Main.AndrewBlaich" version="1"

LockDown 28 - 15 Nov 2007 - Main.AndrewBlaich
Line: 1 to 1
 
META TOPICPARENT name="Projects"

Lockdown

Line: 11 to 11
  The administrator of an enterprise network has a responsibility to enforce the policies on the network. Yet, most security mechanisms do not map well to the intended policies. This has been due to the prevalence of simplistic tools that have poor enforcement but, yet are easy to manage. While advanced commercial solutions do exist that have stronger enforcement, they are significantly harder to manage. To that end, we propose Lockdown, a policy-oriented security approach that builds on the concept of local context to deliver a lighter weight approach to enterprise network security while striking a balance between the level of enforcement and level of management available to the network administrator. We describe how the Lockdown approach streamlines the process of network security management from network auditing to visualization to policy mapping to enforcement to validation. We demonstrate the strength of Lockdown through detailed assessments of an enterprise university network to show how local context significantly improves network management for the system administrator.
Deleted:
<
<
Slides for CSE-SRS-2007 Poster Symposium.
  Read about the LockdownStructure.

Added:
>
>

Lockdown

  • LSM Enforcement
  • Monitor data gathering
 

Publications:

  • Thesis Q. Liao, "Improving Network Insight Through Local Context Gathering and Analysis," Master Thesis, University of Notre Dame. Adviser: Dr. Aaron Striegel, Committee: Dr. Douglas Thain, Dr. Nitesh Chawla.
  • USENIX Security '07 Poster: Presented by A. Blaich
Added:
>
>
  • Slides for CSE-SRS-2007 Poster Symposium.
 

Source Code

NOTE: all code is in constant development, newer versions will be posted as they are made available, use at your own risk!

LockDown 27 - 25 Oct 2007 - Main.AndrewBlaich
Line: 1 to 1
 
META TOPICPARENT name="Projects"

Lockdown

Line: 11 to 11
  The administrator of an enterprise network has a responsibility to enforce the policies on the network. Yet, most security mechanisms do not map well to the intended policies. This has been due to the prevalence of simplistic tools that have poor enforcement but, yet are easy to manage. While advanced commercial solutions do exist that have stronger enforcement, they are significantly harder to manage. To that end, we propose Lockdown, a policy-oriented security approach that builds on the concept of local context to deliver a lighter weight approach to enterprise network security while striking a balance between the level of enforcement and level of management available to the network administrator. We describe how the Lockdown approach streamlines the process of network security management from network auditing to visualization to policy mapping to enforcement to validation. We demonstrate the strength of Lockdown through detailed assessments of an enterprise university network to show how local context significantly improves network management for the system administrator.
Added:
>
>
Slides for CSE-SRS-2007 Poster Symposium.
 Read about the LockdownStructure.


LockDown 26 - 23 Oct 2007 - Main.AndrewBlaich
Line: 1 to 1
 
META TOPICPARENT name="Projects"

Lockdown

Line: 7 to 7
 Students: Andrew Blaich, Qi Liao, Brian Sullivan, Greg Allan, Ben Roesch

Lockdown Overview:

Added:
>
>
  The administrator of an enterprise network has a responsibility to enforce the policies on the network. Yet, most security mechanisms do not map well to the intended policies. This has been due to the prevalence of simplistic tools that have poor enforcement but, yet are easy to manage. While advanced commercial solutions do exist that have stronger enforcement, they are significantly harder to manage. To that end, we propose Lockdown, a policy-oriented security approach that builds on the concept of local context to deliver a lighter weight approach to enterprise network security while striking a balance between the level of enforcement and level of management available to the network administrator. We describe how the Lockdown approach streamlines the process of network security management from network auditing to visualization to policy mapping to enforcement to validation. We demonstrate the strength of Lockdown through detailed assessments of an enterprise university network to show how local context significantly improves network management for the system administrator.

Read about the LockdownStructure.

Line: 23 to 25
 
  • Monitor: The Monitor is installed on each host within the network and is responsible for collecting the local context [netstat, ps, and lsof data] and sending it to the collecting server.
Changed:
<
<
>
>
 
  • Enforcer: The Enforcer is a Linux Security Module, LSM, that is responsible for enforcing policy within the kernel.
    • Linux [2.6 kernel]: update coming soon

LockDown 25 - 16 Oct 2007 - Main.AndrewBlaich
Line: 1 to 1
 
META TOPICPARENT name="Projects"

Lockdown

Line: 15 to 15
 

Publications:

  • Thesis Q. Liao, "Improving Network Insight Through Local Context Gathering and Analysis," Master Thesis, University of Notre Dame. Adviser: Dr. Aaron Striegel, Committee: Dr. Douglas Thain, Dr. Nitesh Chawla.
Changed:
<
<
>
>
 

Source Code

NOTE: all code is in constant development, newer versions will be posted as they are made available, use at your own risk!
Line: 26 to 26