Title :
A Statistical Approach for Fingerprinting Probing Activities
Author :
Bou-Harb, Elias ; Debbabi, Mourad ; Assi, Chadi
Author_Institution :
NCFTA, Concordia Univ., Montreal, QC, Canada
Abstract :
Probing is often the primary stage of an intrusion attempt that enables an attacker to remotely locate, target, and subsequently exploit vulnerable systems. This paper attempts to investigate whether the perceived traffic refers to probing activities and which exact scanning technique is being employed to perform the probing. Further, this work strives to examine probing traffic dimensions to infer the `machinery´ of the scan, whether the probing activity is generated from a software tool or from a worm/bot net and whether the probing is random or follows a certain predefined pattern. Motivated by recent cyber attacks that were facilitated through probing, limited cyber security intelligence related to the mentioned inferences and the lack of accuracy that is provided by scanning detection systems, this paper presents a new approach to fingerprint probing activity. The approach leverages a number of statistical techniques, probabilistic distribution methods and observations in an attempt to understand and analyze probing activities. To prevent evasion, the approach formulates this matter as a change point detection problem that yielded motivating results. Evaluations performed using 55 GB of real dark net traffic shows that the extracted inferences exhibit promising accuracy and can generate significant insights that could be used for mitigation purposes.
Keywords :
computer network security; invasive software; statistical distributions; telecommunication traffic; botnet; change point detection problem; cyber attacks; cyber security intelligence; darknet traffic; fingerprint probing activity; intrusion attempt; perceived traffic; probabilistic distribution method; probing traffic dimensions; scanning detection systems; software tool; statistical techniques; worm; Accuracy; Computer crime; Correlation; Cyberspace; Doped fiber amplifiers; Educational institutions; Cyber Security Capability; Probing; Scanning;
Conference_Titel :
Availability, Reliability and Security (ARES), 2013 Eighth International Conference on
Conference_Location :
Regensburg
DOI :
10.1109/ARES.2013.9