A Hybrid Stepping-Stone Detection Algorithm to Counter Packet Jittering Evasion

被引:0
|
作者
Huang, Shou-Hsuan Stephen [1 ]
Ding, Wei [1 ]
机构
[1] Univ Houston, Dept Comp Sci, Houston, TX 77204 USA
来源
关键词
network security; intrusion detection; stepping-stone; intrusion evasion; packet jittering;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Hackers often use a chain of intermediate stepping-stone hosts to hide their identity before launching an attack to a particular target. This type of stepping-stone attack can be detected by applying timing-based correlation algorithms on the connections in and out of a stepping-stone host. However, hackers can add chaff packets or jitter the original packets to decrease the detection rate of these correlation-based algorithms. This paper proposes a novel method to detect intrusions under the influence of packet jittering. We first show how the distribution of the inter-arrival time gaps of a jittered connection differs from connections without jittering. An algorithm was designed to detect jittered stream of packets based on the above model. The impact of the jittering probability model on the detection rate and the impact of distribution parameters on the detection rate are presented. A hybrid method to detect stepping-stone detection is proposed which combines a correlation algorithm and our jittering detection algorithm to achieve a better result. This hybrid algorithm gives a much more robust solution to the stepping-stone detection problem.
引用
收藏
页码:83 / 92
页数:10
相关论文
共 37 条