Sciweavers

ESORICS
2002
Springer

Inter-Packet Delay Based Correlation for Tracing Encrypted Connections through Stepping Stones

14 years 11 months ago
Inter-Packet Delay Based Correlation for Tracing Encrypted Connections through Stepping Stones
Network based intrusions have become a serious threat to the users of the Internet. Intruders who wish to attack computers attached to the Internet frequently conceal their identity by staging their attacks through intermediate "stepping stones". This makes tracing the source of the attack substantially more difficult, particularly if the attack traffic is encrypted. In this paper, we address the problem of tracing encrypted connections through stepping stones. The incoming and outgoing connections through a stepping stone must be correlated to accomplish this. We propose a novel correlation scheme based on inter-packet timing characteristics of both encrypted and unencrypted connections. We show that (after some filtering) inter-packet delays (IPDs) of both encrypted and unencrypted, interactive connections are preserved across many router hops and stepping stones. The effectiveness of this method for correlation purposes also requires that timing characteristics be distinct...
Xinyuan Wang, Douglas S. Reeves, Shyhtsun Felix Wu
Added 24 Dec 2009
Updated 24 Dec 2009
Type Conference
Year 2002
Where ESORICS
Authors Xinyuan Wang, Douglas S. Reeves, Shyhtsun Felix Wu
Comments (0)