Table of Contents
Syslog-Sign and Syslog-Auth
Overview of Presentation
Introduction: Context
Introduction: What We Want From Syslog-Sign
Security Goals
What's Not Possible?
Overview of Syslog-Sign
Messages as Sent
PPT Slide
PPT Slide
PPT Slide
Out-of-Order Messages/Blocks
Messages as Received: A Big Mess
PPT Slide
Missing or Garbled/Altered Messages
Duplicate Messages
Some Terminology
Important Concepts: Signature Group
Important Concepts: Reboot Sessions and Session IDs
Message Index Numbers
Syslog-Sign Messages
Signature Blocks--Structure
Signature Blocks--Fields
Signature Blocks--Fields
Signature Blocks, Cont'd
Signature Blocks, Cont'd
Signature Blocks, Cont'd
Signature Block, Cont'd
Signature Block, Cont'd
Notes: Variable Length Fields
Notes: Redundancy
Missing Signature Blocks
Certificate Blocks
Certificate Blocks, Cont'd
Certificate Blocks, Cont'd
Certificate Blocks, Cont'd
Certificate Blocks, Cont'd
Certificate Blocks, Cont'd
Certificate Blocks, Cont'd
Certificate Blocks, Cont'd
Certificate Blocks, Cont'd
Certificate Blocks, Cont'd
Offline Review
Online Review
Summary: Syslog-Sign Plusses
Syslog-Sign: Minuses
Syslog-Auth | Syslog-Sign
Syslog-Auth and Syslog-Sign
Overview of Syslog-Auth
PPT Slide
PPT Slide
Syslog-Auth: Key Concepts
Authentication Blocks: Format
Auth Block Format
Authentication Block--Components
Authentication Block--Components
Authentication Block--Components
Auth Block Component:Session IDs
Session IDs: Cont'd
Authentication Block--Components
Forwarding Block
How it Works: Device->Collector
How It Works: Forwarded Messages
Forwarded Messages: Status Flags
Forwarded Messages: Cont'd
Why Sticky Flags Matter
More Sticky Flags
Syslog-Auth:Plusses and Minuses
Future of Syslog-Auth
|