Exposure Maps: Removing Reliance on Attribution During Scan Detection

Exposure Maps: Removing Reliance on Attribution During Scan Detection
复制标题

曝光图:消除扫描检测期间对归因的依赖

DOI:
--
复制
发表时间:
2006
期刊:
USENIX conference on Hot topics in security
影响因子:
--
通讯作者:
E. Kranakis
E. Kranakis
中科院分区:
--
文献类型:
--
作者:
D. Whyte;P. V. Oorschot;E. Kranakis

文献摘要

被引文献

相似文献

当前的扫描检测算法基于一个基本假设,即扫描活动可以归因于有意义的特定来源(即根本原因或扫描控制器)。复杂的扫描活动,包括使用僵尸网络、空闲扫描和一次性系统,违反了这一假设。我们提出了一类扫描检测算法,它关注的是被扫描的是什么,而不是谁在执行扫描。我们遵循这一思想,引入暴露地图的概念,并报告了一个初步的概念验证,该概念验证允许人们:(1)估计由于扫描活动而暴露给对手的信息或暴露;(2)检测复杂的或有针对性的扫描活动,其足迹低至单个数据包或事件;以及(3)发现网络暴露的实时变化,这可能表明攻击成功。
Current scanning detection algorithms are based on an underlying assumption that scanning activity can be attributed to a meaningful specific source (i.e. the root cause or scan controller). Sophisticated scanning activity including the use of botnets, idle scanning, and throwaway systems violates this assumption. We propose a class of scanning detection algorithms that focus on what is being scanned for instead of who is performing the scanning. We pursue this idea, introduce the concept of exposuremaps, and report on a preliminary proof-of-concept that allows one to: (1) estimate the information or exposures revealed to an adversary as a result of scanning activity; (2) detect sophisticated or targeted scanning activity with a footprint as low as a single packet or event; and (3) discover real-time changes in network exposures that may be indicative of a successful attack.