System Security Management via SNMP

نویسندگان

  • F. Stamatelopoulos
  • G. Koutepas
  • B. Maglaris
چکیده

We present a framework for managing system security, based on an SNMP Management Information Base (MIB), namely the System Security MIB (SSEC MIB). We have defined managed objects and completed the ASN.1 description of the MIB that embeds them. The related security management functions are mainly focused on monitoring, external script execution for system security scanning and access control. The main goal of this work is to introduce the semantics and a standard interface that will allow the realisation of specific system security management functions independently of the underlying architecture. Our definitions pertain to multi-user, multi-tasking operating systems that support TCP/IP communications and a prototype of the SSEC MIB is under development for UNIX systems. The proposed management framework follows the manager/agent paradigm: an agent is installed on every system connected to the network, communicating with one or more central managers through a management protocol. We have tried not to heavily rely on polling for the manager-agent interaction by using as much as possible asynchronous notification mechanisms and allowing some limited delegated functionality for the agent (scheduling and handling of local scripts). The manager scans the agents for security information, sets specific parameters for monitoring and script execution and receives asynchronous notifications on specific events, whereas the agent maintains a MIB that provides the system-independent interface semantics, executes scripts for security scanning, performs monitoring & logging and generates the asynchronous notification PDUs.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Management of Network Security Applications

Security policy and security techniques have been major research topics for a long time, but relatively little work has been reported on management of distributed security applications. This paper reviews several security management projects and related security research to date. We present a core set of security managed objects for use with the Simple Network Management Protocol (SNMP). Securi...

متن کامل

RFC 5953 TLS Transport Model for SNMP August

This document describes a Transport Model for the Simple Network Management Protocol (SNMP), that uses either the Transport Layer Security protocol or the Datagram Transport Layer Security (DTLS) protocol. The TLS and DTLS protocols provide authentication and privacy services for SNMP applications. This document describes how the TLS Transport Model (TLSTM) implements the needed features of a S...

متن کامل

Transport Security Model for the Simple Network Management Protocol (SNMP)

This memo describes a Transport Security Model for the Simple Network Management Protocol (SNMP). This memo also defines a portion of the Management Information Base (MIB) for monitoring and managing the Transport Security Model for SNMP. Table of

متن کامل

White Paper Remote Management: SNMP Sub-agent for Intel® Server Hardware

Simple Network Management Protocol (SNMP) is used ubiquitously to monitor and control any device over the network by exchanging SNMP messages. The SNMP, defined by IETF [1], has gained significant popularity among the software, hardware, telecom, and network industries. SNMP was derived from its predecessor SGMP (Simple Gateway Management Protocol). This is considered as a de facto and standard...

متن کامل

Implementation and Performance Analysis of SNMP on a TLS/TCP Base

There is recent interest in exploring SNMP/TCP in addition to the current use of SNMP/UDP due to performance benefits for bulk transfer as well as to simplify management applications. If SNMP is implemented over TCP, then TLS is a natural choice for security. However, it must be demonstrated that the additional overhead associated with TLS is not excessive. We show this by implementing SNMP on ...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 1997