Profiling distributed connection chains. (19th February 2008)
- Record Type:
- Journal Article
- Title:
- Profiling distributed connection chains. (19th February 2008)
- Main Title:
- Profiling distributed connection chains
- Authors:
- Almulhem, Ahmad
Traore, Issa - Abstract:
- A key challenge in network forensics arises because of 'attackers' ability to move around in the network, which results in creating a chain of connections; commonly known as connection chains. They are widely used by attackers to stay anonymous and/or to confuse the forensic process. Investigating connection chains can be further complicated when several IP addresses are used in the attack. In this paper, we highlight this challenging problem. We then propose a solution through hacker profiling. Our solution includes a novel hacker model that integrates information about a hacker's linguistic, operating system and time of activity. It also includes an algorithm to operate on the proposed model. We establish the effectiveness of the proposed approach through several simulations and an evaluation with a real attack data.
- Is Part Of:
- International journal of communication networks and distributed systems. Volume 1:Number 1(2008)
- Journal:
- International journal of communication networks and distributed systems
- Issue:
- Volume 1:Number 1(2008)
- Issue Display:
- Volume 1, Issue 1 (2008)
- Year:
- 2008
- Volume:
- 1
- Issue:
- 1
- Issue Sort Value:
- 2008-0001-0001-0000
- Page Start:
- 4
- Page End:
- 18
- Publication Date:
- 2008-02-19
- Subjects:
- network security -- connection chains -- stepping stones -- alert correlation -- network forensics -- spatial hacking -- fingerprinting -- hacker profiling -- simulation -- network attacks
Computer networks -- Periodicals
Telecommunication systems -- Periodicals
Electronic data processing -- Distributed processing -- Periodicals
004.6 - Journal URLs:
- http://www.inderscience.com/jhome.php?jcode=ijcnds ↗
http://www.inderscience.com/ ↗ - Languages:
- English
- ISSNs:
- 1754-3916
- Deposit Type:
- Legaldeposit
- View Content:
- Available online (eLD content is only available in our Reading Rooms) ↗
- Physical Locations:
- British Library DSC - BLDSS-3PM
British Library HMNTS - ELD Digital store - Ingest File:
- 8429.xml