Advancing Protocol Diversity in Network Security Monitoring
Jan Grash\"ofer, Peter Oettig, Robin Sommer, Tim Wojtulewicz, Hannes, Hartenstein

TL;DR
This paper enhances network security monitoring by developing a flexible, modular architecture that supports diverse lower-layer protocols, improving performance and enabling detection of industrial protocol attacks.
Contribution
It introduces a new architecture for NSMs that allows flexible integration of lower-layer protocols, demonstrated through implementation in Zeek and evaluation of performance impacts.
Findings
Array-based dispatching structures are practical for performance.
Migration to new protocol interfaces improves modularity.
Implementation supports industrial protocols and attack detection.
Abstract
With information technology entering new fields and levels of deployment, e.g., in areas of energy, mobility, and production, network security monitoring needs to be able to cope with those environments and their evolution. However, state-of-the-art Network Security Monitors (NSMs) typically lack the necessary flexibility to handle the diversity of the packet-oriented layers below the abstraction of TCP/IP connections. In this work, we advance the software architecture of a network security monitor to facilitate the flexible integration of lower-layer protocol dissectors while maintaining required performance levels. We proceed in three steps: First, we identify the challenges for modular packet-level analysis, present a refined NSM architecture to address them and specify requirements for its implementation. Second, we evaluate the performance of data structures to be used for protocol…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Code & Models
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsNetwork Security and Intrusion Detection · Software-Defined Networks and 5G · Network Packet Processing and Optimization
