arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.00954cs.CRcs.NIcs.OS

日志框架对BIND9的影响

Influence of Logging Frameworks on Bind9

Max Schrötter, Hannes Signer, Bettina Schnor

首次发表
浏览论文内容

中文总结 AI 辅助

本研究分析了日志框架对BIND9的影响,发现Fail2Ban监控BIND9的配置可被低流量绕过,提出高性能日志IPC框架FIPS,其开销极小且能提升IPS封禁恶意客户端的速度。

中文摘要 AI 辅助

基于主机的入侵防御系统(IPS)依赖应用程序日志来检测和拦截恶意活动。然而,在现代高速网络中,日志子系统本身会成为瓶颈:攻击者只需生成足够流量来压垮应用程序的日志管道,丢弃关键痕迹,即可隐藏踪迹。在本研究中,我们表明,诸如Fail2Ban监控BIND9这类广泛部署的配置,可通过不到65 Mbps的DNS流量被绕过。此外,我们发现当用高性能等效组件替换IPS架构的核心部分(iptables替换为eBPF,正则表达式匹配替换为Hyperscan)时,日志后端本身会成为瓶颈。因此,我们提出FIPS,一款专为高性能日志设计的新型IPC,它绕过内核并将日志消息的复制降至最低。FIPS使用每线程无锁共享内存环形缓冲区,支持多个独立消费者按自身速率读取同一日志流,既提供原生API,也可作为syslog接口的替代方案。我们对BIND9的评估显示,与禁用日志相比,FIPS几乎无额外开销,记录的请求数量超过所有其他评估框架,且使IPS封禁恶意客户端的速度比使用文件日志时快2.5倍,同时可维持每秒一百万请求的2^16个攻击客户端。

英文摘要

Host-based Intrusion Prevention Systems (IPS) rely on application logs to detect and block malicious activity. However, on modern high-speed networks the logging subsystem itself becomes a bottleneck: an attacker can hide traces simply by generating enough traffic to overwhelm the application's log pipeline, dropping crucial traces. In this work, we show that widely deployed setups such as Fail2Ban monitoring BIND9 can be defeated with less than 65 Mbps of DNS traffic. Further, we show that when replacing core components of the IPS architecture with their higher-performance equivalent, iptables with eBPF and regex matching with Hyperscan, the logging backends themselves become the bottleneck. Therefore, we present FIPS, a new IPC designed for high-performance logging that bypasses the kernel and reduces copying of the log messages to a minimum. FIPS uses per-thread lock free shared memory ring buffers, supporting multiple independent consumers reading the same log stream at their own pace. FIPS offers both a native API and a drop-in replacement for the syslog interface. Our evaluation with BIND 9 shows that FIPS introduces almost no overhead compared to disabled logging, logs more requests than any other evaluated framework, and enables the IPS to ban malicious clients $2.5\times$ faster than with file logging while sustaining $2^{16}$ attacking clients at one million requests per second.

发表机构

  • University of Potsdam(波茨坦大学)

机构由 AI 辅助整理,请以论文原文为准。

↑