• DocumentCode
    2954960
  • Title

    Stepping-stone detection algorithm based on order preserving mapping

  • Author

    Ying-Wei Kuo ; Shou-Hsuan ; Huang, Shanjin

  • Author_Institution
    Dept. of Comput. Sci., Univ. of Houston, Houston, TX
  • Volume
    2
  • fYear
    2007
  • fDate
    5-7 Dec. 2007
  • Firstpage
    1
  • Lastpage
    8
  • Abstract
    Intruders often do not attack victim hosts directly from their own hosts so as not to reveal their identity. Instead, intruders perform their attacks through a sequence of intermediary hosts before attacking the target. This type of attack is known as a "stepping-stone attack". Stepping-stone detection is to determine if a host machine is being used as a stepping-stone by attackers. In this paper, we propose an algorithm for stepping-stone detection using a pervious mapping-based detection method. The technique reduces the detection problem to finding a mapping between two streams of packets. If our algorithm cannot find the mapping, then no such mapping exists. But if there is a mapping, then the proposed algorithm is guaranteed to find one and the solution will always be the one with minimum indexed. We provide the proof of the correctness of the algorithms. Furthermore, the algorithm has a low time complexity. The paper also discusses the effect of chaff packets on the ability to detect stepping-stones.
  • Keywords
    computational complexity; security of data; chaff packets; order preserving mapping; stepping-stone detection algorithm; Stepping-stone; algorithm; connection chain; intrusion detection; mappings;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Parallel and Distributed Systems, 2007 International Conference on
  • Conference_Location
    Hsinchu
  • ISSN
    1521-9097
  • Print_ISBN
    978-1-4244-1889-3
  • Electronic_ISBN
    1521-9097
  • Type

    conf

  • DOI
    10.1109/ICPADS.2007.4447772
  • Filename
    4447772