SafeGuard:一种用于实时端点威胁检测与响应的轻量级客户端-服务器架构
SafeGuard: A Lightweight Client-Server Architecture for Real-Time Endpoint Threat Detection and Response
浏览论文内容
中文总结 AI 辅助
针对小型和资源受限组织,提出SafeGuard轻量级客户端-服务器架构用于实时端点威胁检测与响应。通过基于签名比较检测威胁,利用多种安全技术保障通信安全,经测试验证其能提供实时端点可见性且无商业许可成本,虽有局限但贡献显著。
中文摘要 AI 辅助
端点设备仍是网络攻击的主要目标,但商业端点检测与响应(EDR)平台对小型和资源受限组织来说成本过高且操作复杂。本文提出SafeGuard,一种用于实时端点监控、威胁报告和管理响应的轻量级三层客户端-服务器架构。系统包括基于Flutter的端点代理(扩展Kotlin用于安卓系统访问)、用于设备认证和协调安全通信的中央服务器以及用于实时监控和远程操作的管理仪表盘。威胁检测通过与维护的威胁数据库进行基于签名的比较实现,优先考虑低计算开销、可解释性和易于部署。通信安全通过TLS上的WebSocket(WSS)、JSON Web Token(JWT)认证和基于HMAC的消息完整性验证实现。通过多种测试评估系统,在模拟50个并发端点部署下,平均命令调度延迟约1.5秒,负载下低于2秒,无效认证令牌被拒绝,手动SQL注入和重放尝试未成功。结果表明开源技术栈可提供实时端点可见性和协调管理响应且无商业许可成本。贡献在于架构和实证方面,当前局限包括依赖静态威胁签名、专注安卓实现和受控环境评估。
英文摘要
Endpoint devices remain a primary target for cyberattacks, yet commercial Endpoint Detection and Response (EDR) platforms are often too costly and operationally complex for small and resource-constrained organizations. This paper presents SafeGuard, a lightweight three-tier client-server architecture for real-time endpoint monitoring, threat reporting, and administrative response. The system comprises a Flutter-based endpoint agent extended with Kotlin for Android system access, a Node.js central server that authenticates devices and coordinates secure communication, and an administrative dashboard for live monitoring and remote actions such as device locking, application removal, and warning notification dispatch. Threat detection is implemented through signature-based comparison against a maintained threat database, prioritizing low computational overhead, explainability, and ease of deployment over generalized anomaly detection. Communication security is achieved using WebSocket over TLS (WSS), JSON Web Token (JWT) authentication, and HMAC-based message integrity verification. The system was evaluated through unit, integration, system, load, and preliminary security testing. Under a simulated deployment of 50 concurrent endpoints, average command-dispatch latency was approximately 1.5 seconds and remained below 2 seconds under load. Invalid authentication tokens were rejected, while manual SQL injection and replay attempts were unsuccessful in the evaluated scenarios. The results demonstrate that an open-source technology stack can provide real-time endpoint visibility and coordinated administrative response without commercial licensing costs. The contribution is architectural and empirical rather than algorithmic, with current limitations including reliance on static threat signatures, Android-focused implementation, and controlled-environment evaluation.