Evading Stepping Stone Detection Under the Cloak of Streaming Media
نویسندگان
چکیده
Network-based intrusions have become a serious treat to the users of the Internet. To help cover their tracks, attackers launch attacks from a series of previously compromised systems called stepping stones. Timing correlations on incoming and outgoing packets can lead to detection of the stepping stone and can be used to trace the attacker through each link. Existing approaches, however, deliberately ignore the fact that an attacker can add chaff packets to a traffic stream. An attacker that has complete control over the stepping stone node can install rogue applications that use chaff and introduce delays to make the incoming and outgoing streams have very different traffic characteristics. In this work, we show that such an attacker could avoid detection by the best stepping stone detection methods. We propose a simple buffering technique that could be used by an attacker on a stepping stone to evade detection. In our technique, packets are buffered, selectively dropped, and chaff packets are added to generate constant rate traffic. This traffic has the characteristics of a multimedia stream, such as voice over IP (VoIP), which is quite common on the Internet today. To test the effectiveness of our technique, we simulate both the traffic and detection using a watermark-based timing analysis algorithm. We show that our buffering technique can successfully evade detection with latencies that are reasonable for interactive streams.
منابع مشابه
Evading stepping-stone detection under the cloak of streaming media with SNEAK
Network-based intrusions have become a serious threat to the users of the Internet. To help cover their tracks, attackers launch attacks from a series of previously compromised systems called stepping stones. Timing correlations on incoming and outgoing packets can lead to detection of the stepping stone and can be used to trace the attacker through each link. Prior work has sought to counter t...
متن کاملModeling and Detecting Stepping-Stone Intrusion
Most network intruders launch their attacks through steppingstones to reduce the risks of being discovered. To uncover such intrusions, one prevalent, challenging, and critical way is to compare an incoming connection with an outgoing connection to determine if a computer is used as stepping-stone. In this paper, we present four models to describe stepping-stone intrusion. We also propose the i...
متن کاملStepping-stone Detection Technique Forrecognizing Legitimate and Attack Connections
A stepping-stone connection has always been assumed as an intrusion since the first research on stepping-stone connections twenty years ago. However, not all stepping-stone connections are malicious. This paper proposes an enhanced stepping-stone detection (SSD) technique which is capable to identify legitimate connections from stepping-stone connections. Stepping-stone connections are identifi...
متن کاملDropped Packet Problems in Stepping Stone Detection Method
This paper discusses one of the issues that are not covered by current stepping stone detection based researches. Although dropped packet problems are well-known problem in real network environment, all of the stepping stone detection researches just assume that dropped packet problems do not occur. Stepping stone detection research already in complex condition where each enhancement of the res...
متن کاملIntelligent Network-Based Stepping Stone Detection Approach
This research intends to introduce a new usage of Artificial Intelligent (AI) approaches in Stepping Stone Detection (SSD) fields of research. By using Self-Organizing Map (SOM) approaches as the engine, through the experiment, it is shown that SOM has the capability to detect the number of connection chains that involved in a stepping stones. Realizing that by counting the number of connection...
متن کامل