Robin Sommer's Publications

Bro: An Open Source Network Intrusion Detection System.
Citation key S-BOSNIDS-03
Author Sommer, Robin
Title of Book Security, E-Learning, E-Services, 17. DFN-Arbeitstagung über Kommunikationsnetze
Pages 273–288
Year 2004
ISBN 3-88579-373-3
Location Düsseldorf, Germany
Volume 44
Editor von Knop, Jan and Haverkamp, Wilhelm and Jessen, Eike
Publisher Gesellschaft für Informatik (GI)
Series Lecture Notes in Informatics (LNI)
Abstract Bro is a powerful, but largely unknown open source network intrusion detection system. Based on a sound design, Bro achieves its main goals–-separating policy from mechanisms, efficient operation in high-volumne networks, and withstanding attacks against itself–-by using an event-driven approach. Bro contains several analyzers (e.g. protocol decoders for a variety of network protocols and a signature matching engine), which are by themselves policy-neutral but raise events as an abstraction of the underlying network activity. Based on scripts written in Bro's own powerful scripting language, the user defines event handlers to specify his environment-specific policy.\\ We give an overview about the design and implementation of Bro, describe our experiences with deploying it in large-scale environment, and present some of our extensions.
