Finding a Connection Chain for Tracing Intruders

Finding a Connection Chain for Tracing Intruders
复制标题

DOI:
10.1007/10722599_12
复制
发表时间:
2000-10
期刊:
--
影响因子:
--
通讯作者:
K. Yoda;H. Etoh
K. Yoda;H. Etoh
中科院分区:
其他
文献类型:
--
作者:
K. Yoda;H. Etoh

文献摘要

被引文献

相似文献

入侵者通常通过多个计算机系统链登录,以隐藏他们的来源,然后再闯入他们的目标,这使得追踪变得困难。本文提出了一种寻找入侵者连接链的方法。我们专注于telnet和rlogin作为入侵者通过主机登录的交互式应用程序,该方法包括在Internet上尽可能多的流量点设置数据包监视器,以记录入侵者在数据包级别的活动。当一台主机被入侵并被用作访问另一台主机的直通主机时,我们将该主机上入侵者的数据包日志与我们在整个Internet上记录的日志进行比较,以找到最接近的匹配。我们定义了一个数据包流从另一个连接上的“偏差”,并实现了一个系统来计算偏差。如果偏差很小,则两个连接必须在同一连接链中。我们提出了一些实验结果表明,两个不相关的数据包流的偏差是足够大的,以区分在同一链中的连接上的数据包流的偏差。
Intruders usually log in through a chain of multiple computer systems to hide their origins before breaking into their targets, which makes tracing difficult. In this paper we present a method to find the connection chain of an intruder for tracing back to the origin. We focus on telnet and rlogin as interactive applications intruders use to log in through hosts.The method involves setting up packet monitors at as many traffic points as possible on the Internet to record the activities of intruders at the packet level. When a host is compromised and used as a step-through host to access another host, we compare the packet logs of the intruder at that host to logs we have recorded all over the Internet to find the closest match. We define the ‘deviation’ for one packet stream on a connection from another, and implement a system to compute deviations. If a deviation is small, the two connections must be in the same connection chain. We present some experimental results showing that the deviation for two unrelated packet streams is large enough to be distinguished from the deviation for packet streams on connections in the same chain.