50 likes | 150 Views
Logging Methods. Argus – QoSient, LLC – Carter Bullard <http://www.qosient.com/argus> OpenSource effort and proprietary version Same flow model, performance and scaling Origin/History: Early 1990’s Work at CERT Guerilla work until startup in 1999 Continued analysis/experimentation at CMU
E N D
Logging Methods • Argus – QoSient, LLC – Carter Bullard • <http://www.qosient.com/argus> • OpenSource effort and proprietary version • Same flow model, performance and scaling • Origin/History: • Early 1990’s Work at CERT • Guerilla work until startup in 1999 • Continued analysis/experimentation at CMU • Validation, IDS, web logging (FlowScan-style)
Argus • Applications – audit • Edge Traffic Characterization • Security • Anonymized research data (use analysis) • Traffic accounting • Service/Policy Discovery • who/how/how much • Unexpected service delivery? • QoS validation • Internet Call records • Who talks to whom – not what’s said • Contrast to Carnivore
Advantages Authoritative Transaction flow aggregation Strong flow model/semantic TCP window delta/retrans ICMP aggregation Accurate timestamps TCPdump selection syntax Scalable – multiple probes Flexible – put probe anywhere Subnet/switch/host Limited access to user data Higher level tools for analysis/indexing Disadvantages Technology, no sexy apps Limited documentation Probe Architecture Vs switches, IPSEC, etc Scaling factors DoS vulnerability Argus Flow Logs
Argus • Quick Demo
Interesting Questions • Aggregate transaction analysis • Web trans frames smtp spam • Probes followed by specific connections • Application fingerprinting • Regardless of port • Network service Provision • End2End or Edge2Ether • Ask for a service, not a connection