DocumentCode
2785357
Title
MANTICORE: Masking All Network Traffic via IP Concealment with OpenVPN Relaying to EC2
Author
Butler, Patrick ; Rhodes, Adam ; Hasan, Ragib
Author_Institution
Dept. of Comput. & Inf. Sci., Univ. of Alabama at Birmingham, Birmingham, AL, USA
fYear
2012
fDate
24-29 June 2012
Firstpage
487
Lastpage
493
Abstract
Malware and computer forensic researchers often communicate with malicious servers, either directly or indirectly, through the web browser or other ports utilized by malicious software. Communication with this form of adversary can sometimes necessitate the use of a proxy server in order to conceal the true origin of the researcher´s traffic. Open source projects such as OpenVPN currently offer a structured method for establishing software based virtual private networks (VPNs) between arbitrary clients and servers. Likewise, paradigms exist which allow a user to proxy traffic from one end of a VPN to another, effectively masking the origin of traffic being sent to and from the client system. In this paper, we present MANTICORE - a system that combines ideas from VPN with the instancing functionality of a cloud computing system in order to dynamically mask and reassign the apparent IP address of a researcher´s system. We also present experimental evaluation of our system on Amazon´s Elastic Compute Cloud (EC2).
Keywords
IP networks; cloud computing; invasive software; online front-ends; telecommunication traffic; virtual private networks; Amazon elastic compute cloud; EC2; IP address; IP concealment; MANTICORE; OpenVPN; Web browser; cloud computing system; computer forensic researchers; malicious servers; malicious software; malware; network traffic; proxy traffic; software based virtual private networks; Browsers; IP networks; Routing; Security; Servers; Switches; Virtual private networks; cloud computing; forensics; security;
fLanguage
English
Publisher
ieee
Conference_Titel
Cloud Computing (CLOUD), 2012 IEEE 5th International Conference on
Conference_Location
Honolulu, HI
ISSN
2159-6182
Print_ISBN
978-1-4673-2892-0
Type
conf
DOI
10.1109/CLOUD.2012.29
Filename
6253542
Link To Document