Defending against Probe-Response Attacks

Emmanouil Vasilomanolakis, Noorulla Sharief, Max Mühlhäuser

Publikation: Bidrag til bog/antologi/rapport/konference proceedingKonferenceartikel i proceedingForskningpeer review

1 Citationer (Scopus)

Abstract

With the increase in the sophistication of cyberattacks, collaborative defensive approaches such as Collaborative IDSs (CIDSs) have emerged. CIDSs utilize a multitude of heterogeneous monitors to create a holistic picture of the monitored network. Nowadays, a number of research institutes and companies deploy CIDSs that publish their alert data publicly, over the Internet. Such systems are important for researchers and security administrators as they provide a source of real-world alert data for experimentation. However, a class of attacks exist, called Probe-Response Attacks (PRAs), which can significantly reduce the benefits of a CIDS. In particular, such attacks allow an adversary to detect the network location of the monitors of a CIDS. In this paper, we first study the related work and analyze the various mitigation techniques for defending against PRAs. Subsequently, we propose a novel mitigation mechanism that improves the state of the art. Our method, namely the Shuffle-based PRA Mitigation (SPM), is based on the idea of shuffling the watermarks, so-called markers, which the adversary requires to successfully perform a PRA. By doing so the whole process of the attack is disrupted leading to a very small number of identified monitors. Our experimental results suggest that our proposed method significantly reduces the impact of a PRA whilst it does not introduce a trade-off for the usability of the data produced by the CIDS.

OriginalsprogEngelsk
TitelProceedings of the IM 2017 - 2017 IFIP/IEEE International Symposium on Integrated Network and Service Management
RedaktørerProsper Chemouil, Paulo Simoes, Edmundo Madeira, Stefano Secci, Edmundo Monteiro, Luciano Paschoal Gaspary, Carlos Raniery P. dos Santos, Marinos Charalambides
Antal sider6
ForlagIEEE
Publikationsdato20 jul. 2017
Sider1046-1051
Artikelnummer7987436
ISBN (Elektronisk)9783901882890
DOI
StatusUdgivet - 20 jul. 2017
Udgivet eksterntJa
Begivenhed15th IFIP/IEEE International Symposium on Integrated Network and Service Management, IM 2017 - Lisbon, Portugal
Varighed: 8 maj 201712 maj 2017

Konference

Konference15th IFIP/IEEE International Symposium on Integrated Network and Service Management, IM 2017
Land/OmrådePortugal
ByLisbon
Periode08/05/201712/05/2017
SponsorIEEE Communications Society, IFIP Working Group 6.6
NavnProceedings of the IM 2017 - 2017 IFIP/IEEE International Symposium on Integrated Network and Service Management

Bibliografisk note

Publisher Copyright:
© 2017 IFIP.

Fingeraftryk

Dyk ned i forskningsemnerne om 'Defending against Probe-Response Attacks'. Sammen danner de et unikt fingeraftryk.

Citationsformater