DocumentCode
2954960
Title
Stepping-stone detection algorithm based on order preserving mapping
Author
Ying-Wei Kuo ; Shou-Hsuan ; Huang, Shanjin
Author_Institution
Dept. of Comput. Sci., Univ. of Houston, Houston, TX
Volume
2
fYear
2007
fDate
5-7 Dec. 2007
Firstpage
1
Lastpage
8
Abstract
Intruders often do not attack victim hosts directly from their own hosts so as not to reveal their identity. Instead, intruders perform their attacks through a sequence of intermediary hosts before attacking the target. This type of attack is known as a "stepping-stone attack". Stepping-stone detection is to determine if a host machine is being used as a stepping-stone by attackers. In this paper, we propose an algorithm for stepping-stone detection using a pervious mapping-based detection method. The technique reduces the detection problem to finding a mapping between two streams of packets. If our algorithm cannot find the mapping, then no such mapping exists. But if there is a mapping, then the proposed algorithm is guaranteed to find one and the solution will always be the one with minimum indexed. We provide the proof of the correctness of the algorithms. Furthermore, the algorithm has a low time complexity. The paper also discusses the effect of chaff packets on the ability to detect stepping-stones.
Keywords
computational complexity; security of data; chaff packets; order preserving mapping; stepping-stone detection algorithm; Stepping-stone; algorithm; connection chain; intrusion detection; mappings;
fLanguage
English
Publisher
ieee
Conference_Titel
Parallel and Distributed Systems, 2007 International Conference on
Conference_Location
Hsinchu
ISSN
1521-9097
Print_ISBN
978-1-4244-1889-3
Electronic_ISBN
1521-9097
Type
conf
DOI
10.1109/ICPADS.2007.4447772
Filename
4447772
Link To Document