Detecting stepping stones by abnormal causality probability. Issue 10 (23rd June 2014)
- Record Type:
- Journal Article
- Title:
- Detecting stepping stones by abnormal causality probability. Issue 10 (23rd June 2014)
- Main Title:
- Detecting stepping stones by abnormal causality probability
- Authors:
- Wen, Sheng
Wu, Di
Li, Ping
Xiang, Yang
Zhou, Wanlei
Wei, Guiyi
Su, Jinshu
Wang, Xiaofeng
Shi, Weisong
Ray, Indrakshi - Abstract:
- <abstract abstract-type="main" id="sec1037-abs-0001"> <title>Abstract</title> <p id="sec1037-para-0001">Locating the real source of the Internet attacks has long been an important but difficult problem to be addressed. In the real world, attackers can easily hide their identities and evade punishment by relaying their attacks through a series of compromised systems or devices called stepping stones. Currently, researchers mainly use similar features from the network traffic, such as packet timestamps and frequencies, to detect stepping stones. However, these features can be easily destroyed by attackers using evasive techniques. In addition, it is also difficult to implement an appropriate threshold of similarity that can help justify the stepping stones. In order to counter these problems, in this paper, we introduce the consistent causality probability to detect the stepping stones. We formulate the ranges of abnormal causality probabilities according to the different network conditions, and on the basis of it, we further implement to self‐adaptive methods to capture stepping stones. To evaluate our proposed detection methods, we adopt theoretic analysis and empirical studies, which demonstrate accuracy of the abnormal causality probability. Moreover, we compare our proposed methods with previous works. The result shows that our methods in this paper significantly outperform previous works in the accuracy of detection malicious stepping stones, even when evasive techniques<abstract abstract-type="main" id="sec1037-abs-0001"> <title>Abstract</title> <p id="sec1037-para-0001">Locating the real source of the Internet attacks has long been an important but difficult problem to be addressed. In the real world, attackers can easily hide their identities and evade punishment by relaying their attacks through a series of compromised systems or devices called stepping stones. Currently, researchers mainly use similar features from the network traffic, such as packet timestamps and frequencies, to detect stepping stones. However, these features can be easily destroyed by attackers using evasive techniques. In addition, it is also difficult to implement an appropriate threshold of similarity that can help justify the stepping stones. In order to counter these problems, in this paper, we introduce the consistent causality probability to detect the stepping stones. We formulate the ranges of abnormal causality probabilities according to the different network conditions, and on the basis of it, we further implement to self‐adaptive methods to capture stepping stones. To evaluate our proposed detection methods, we adopt theoretic analysis and empirical studies, which demonstrate accuracy of the abnormal causality probability. Moreover, we compare our proposed methods with previous works. The result shows that our methods in this paper significantly outperform previous works in the accuracy of detection malicious stepping stones, even when evasive techniques are adopted by attackers. Copyright © 2014 John Wiley &amp; Sons, Ltd.</p> </abstract> … (more)
- Is Part Of:
- Security and communication networks. Volume 8:Issue 10(2015)
- Journal:
- Security and communication networks
- Issue:
- Volume 8:Issue 10(2015)
- Issue Display:
- Volume 8, Issue 10 (2015)
- Year:
- 2015
- Volume:
- 8
- Issue:
- 10
- Issue Sort Value:
- 2015-0008-0010-0000
- Page Start:
- 1831
- Page End:
- 1844
- Publication Date:
- 2014-06-23
- Subjects:
- Computer networks -- Security measures -- Periodicals
Computer security -- Periodicals
Cryptography -- Periodicals
005.805 - Journal URLs:
- http://onlinelibrary.wiley.com/journal/10.1002/(ISSN)1939-0122 ↗
https://www.hindawi.com/journals/scn/ ↗
http://onlinelibrary.wiley.com/ ↗ - DOI:
- 10.1002/sec.1037 ↗
- Languages:
- English
- ISSNs:
- 1939-0114
- Deposit Type:
- Legaldeposit
- View Content:
- Available online (eLD content is only available in our Reading Rooms) ↗
- Physical Locations:
- British Library HMNTS - ELD Digital store
- Ingest File:
- 3512.xml