50 likes | 159 Vues
Argus is an open-source logging method by QoSient, LLC, offering transaction flow aggregation with strong semantic models and scalability, suited for security, audit, and traffic analysis. It provides accurate timestamps, flexible probe placement, and analytical capabilities for edge traffic characterization, service discovery, and QoS validation.
E N D
Logging Methods • Argus – QoSient, LLC – Carter Bullard • <http://www.qosient.com/argus> • OpenSource effort and proprietary version • Same flow model, performance and scaling • Origin/History: • Early 1990’s Work at CERT • Guerilla work until startup in 1999 • Continued analysis/experimentation at CMU • Validation, IDS, web logging (FlowScan-style)
Argus • Applications – audit • Edge Traffic Characterization • Security • Anonymized research data (use analysis) • Traffic accounting • Service/Policy Discovery • who/how/how much • Unexpected service delivery? • QoS validation • Internet Call records • Who talks to whom – not what’s said • Contrast to Carnivore
Advantages Authoritative Transaction flow aggregation Strong flow model/semantic TCP window delta/retrans ICMP aggregation Accurate timestamps TCPdump selection syntax Scalable – multiple probes Flexible – put probe anywhere Subnet/switch/host Limited access to user data Higher level tools for analysis/indexing Disadvantages Technology, no sexy apps Limited documentation Probe Architecture Vs switches, IPSEC, etc Scaling factors DoS vulnerability Argus Flow Logs
Argus • Quick Demo
Interesting Questions • Aggregate transaction analysis • Web trans frames smtp spam • Probes followed by specific connections • Application fingerprinting • Regardless of port • Network service Provision • End2End or Edge2Ether • Ask for a service, not a connection