Network Forensics on Packet Fingerprints
نویسندگان
چکیده
We present an approach to network forensics that makes it feasible to trace the content of all traffic that passed through the network via packet content fingerprints. We develop a new data structure called the “Rolling Bloom Filter” (RBF), which is based on a generalization of the Rabin-Karp stringmatching algorithm. This merges the two key advantages of space efficiency and an efficient content matching mechanism. This also achieves analytically predictable False Positive Rates that can be controlled by tuning the RBF parameters. Leveraging upon these insights, we have designed and implemented a practical Network Forensic System that gives the ability to reconstruct the sequence of events for post-incident analysis.
منابع مشابه
JPEG Quantization Tables Forensics: A Statistical Approach
Many digital image forensics techniques extracting various fingerprints are dependent on data on digital images from an unknown environment. As often software modifications leave no appropriate traces in images metadata, critical inconveniences and miscalculations of fingerprints arise. This is the problem addressed in this paper. Modeling information noise in image metadata, we introduce a sta...
متن کاملThe Design of Huge Amounts of Information Network Forensics System in View of the Network Crime Prevention
The advent of the information age has brought great convenience to people's life, at the same time all kinds of cyber-crimes have become increasingly rampant, causing great damage to people's life. To build a network forensics data which is based on multi Agent system model, which is further based on multi Agent technology, by means of an agent, in a distributed implementation method of network...
متن کاملTowards Provably Invisible Network Flow Fingerprints
Network traffic analysis reveals important information even when messages are encrypted. We consider active traffic analysis via flow fingerprinting by invisibly embedding information into packet timings of flows. In particular, assume Alice wishes to embed fingerprints into flows of a set of network input links, whose packet timings are modeled by Poisson processes, without being detected by a...
متن کاملNew High Secure Network Steganography Method Based on Packet Length
In network steganography methods based on packet length, the length of the packets is used as a carrier for exchanging secret messages. Existing methods in this area are vulnerable against detections due to abnormal network traffic behaviors. The main goal of this paper is to propose a method which has great resistance to network traffic detections. In the first proposed method, the sender embe...
متن کاملAvoiding Cyber-attacks to DMZ and Capturing Forensics from Intruders Using Honeypots
Nowadays, honeypots are widely used to divert attackers from the original target and keep them busy within a decoy environment. DeMilitarized Zone (DMZ) is an important zone for network administrators, because many of the services to the public network is provided at this zone. Many of the security tools such as firewalls, intrusion detection systems and several other secu...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2006