• DocumentCode
    246158
  • Title

    Evaluating a Dynamic Internet Threat Monitoring Method for Preventing PN Code-Based Localization Attack

  • Author

    Narita, Masaki ; Ogura, Kanayo ; Bista, Bhed Bahadur ; Takata, Toyoo

  • fYear
    2014
  • fDate
    10-12 Sept. 2014
  • Firstpage
    271
  • Lastpage
    278
  • Abstract
    The Internet threat monitoring systems are developed to grasp malicious activities on the Internet. Those systems consist of a data center and sensors deployed on the Internet. Sensors capture malicious packets and report to the data center. The data center investigates the latest trend of attacks by analyzing those packets and the result is open to the public. To publish precise monitored results, sensors are deployed in secret and hidden from outside. On the other hand, attackers intend to detect sensors for evading them. This attack is known as localization attacks to Internet threat monitoring systems. Recent localization attacks adopting PN code is sophisticated and effective countermeasure is not developed yet. Therefore, we propose a dynamic Internet threat monitoring method. This method switches sensors whose monitored results that reflect to published results in a data center as a countermeasure for PN code-based localization attack. We evaluated our method from the aspect of tolerance to the attack by applying raw captured packets provided by nicter. Meanwhile, the existing systems always publish monitored results reported by whole sensors. Therefore, the information that our method provides would decrease compared to that of the existing systems. However, we show that the decrease of information is sufficiently small.
  • Keywords
    Internet; computer centres; computer network security; computerised monitoring; sensors; PN code-based localization attack prevention; data center; dynamic Internet threat monitoring method; malicious activities; malicious packets; sensors; Correlation; Internet; Monitoring; Ports (Computers); Schedules; Sensor systems; Internet threat monitoring system; darknet; localization attack;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Network-Based Information Systems (NBiS), 2014 17th International Conference on
  • Conference_Location
    Salerno
  • Print_ISBN
    978-1-4799-4226-8
  • Type

    conf

  • DOI
    10.1109/NBiS.2014.57
  • Filename
    7023964