Ecole d'ingénieur et centre de recherche en télécommunications

Internet attack knowledge discovery via clusters and cliques of attack traces

Pouget, Fabien;Dacier, Marc;Zimmerman, J;Clark, A;Mohay, G

Journal of Information Assurance and Security, Volume 1, Issue 1, March 2006

There is an increasing awareness of the growing influence of organized entities involved in today’s Internet attacks. However, there is no easy way to discriminate between the observed malicious activities of script kiddies and professional organizations, for example. For more than two years, the Leurré.com project has collected data on a worldwide scale amenable to such analysis. Previous publications have highlighted the usefulness of so called attack clusters to provide some insight into the different tools used to attack Internet sites. In this paper, we introduce a new notion, namely cliques of clusters, as an automated knowledge discovery method. Cliques provide analysts with some refined information about how, and potentially by whom, attack tools are used. We provide some examples of the kind of information that they can provide. We also address the limitations of the approach by showing that some interesting attack characteristics, namely Inter Arrival Times (IATs) of packets in the attack flows, are only partially taken into account by this approach.

Document Doi Bibtex

Mots Clés:honeypots;traffic analysis;Internet attacks;malware;computer forensics
Type:Journal
Langue:English
Date:
Département:Réseaux et Sécurité
Eurecom ref:2128
Copyright: © Dynamic publishers. Personal use of this material is permitted. The definitive version of this paper was published in Journal of Information Assurance and Security, Volume 1, Issue 1, March 2006 and is available at : http://www.softcomputing.net/jias/a3.pdf
Bibtex: @article{EURECOM+2128, doi = {http://www.softcomputing.net/jias/a3.pdf}, year = {2006}, month = {03}, title = {{I}nternet attack knowledge discovery via clusters and cliques of attack traces}, author = {{P}ouget, {F}abien and {D}acier, {M}arc and {Z}immerman, {J} and {C}lark, {A} and {M}ohay, {G}}, journal = {{J}ournal of {I}nformation {A}ssurance and {S}ecurity, {V}olume 1, {I}ssue 1, {M}arch 2006}, url = {http://www.eurecom.fr/publication/2128} }
Voir aussi: