DocumentCode
246158
Title
Evaluating a Dynamic Internet Threat Monitoring Method for Preventing PN Code-Based Localization Attack
Author
Narita, Masaki ; Ogura, Kanayo ; Bista, Bhed Bahadur ; Takata, Toyoo
fYear
2014
fDate
10-12 Sept. 2014
Firstpage
271
Lastpage
278
Abstract
The Internet threat monitoring systems are developed to grasp malicious activities on the Internet. Those systems consist of a data center and sensors deployed on the Internet. Sensors capture malicious packets and report to the data center. The data center investigates the latest trend of attacks by analyzing those packets and the result is open to the public. To publish precise monitored results, sensors are deployed in secret and hidden from outside. On the other hand, attackers intend to detect sensors for evading them. This attack is known as localization attacks to Internet threat monitoring systems. Recent localization attacks adopting PN code is sophisticated and effective countermeasure is not developed yet. Therefore, we propose a dynamic Internet threat monitoring method. This method switches sensors whose monitored results that reflect to published results in a data center as a countermeasure for PN code-based localization attack. We evaluated our method from the aspect of tolerance to the attack by applying raw captured packets provided by nicter. Meanwhile, the existing systems always publish monitored results reported by whole sensors. Therefore, the information that our method provides would decrease compared to that of the existing systems. However, we show that the decrease of information is sufficiently small.
Keywords
Internet; computer centres; computer network security; computerised monitoring; sensors; PN code-based localization attack prevention; data center; dynamic Internet threat monitoring method; malicious activities; malicious packets; sensors; Correlation; Internet; Monitoring; Ports (Computers); Schedules; Sensor systems; Internet threat monitoring system; darknet; localization attack;
fLanguage
English
Publisher
ieee
Conference_Titel
Network-Based Information Systems (NBiS), 2014 17th International Conference on
Conference_Location
Salerno
Print_ISBN
978-1-4799-4226-8
Type
conf
DOI
10.1109/NBiS.2014.57
Filename
7023964
Link To Document