• DocumentCode
    2388728
  • Title

    A mark association-based investigation of attack scenarios in communication networks

  • Author

    Djemaiel, Yacine ; Rekhis, S. ; Boudriga, Noureddine

  • Author_Institution
    CN&S Res. Lab., Univ. of Carthage, Tunis, Tunisia
  • fYear
    2012
  • fDate
    10-15 June 2012
  • Firstpage
    6673
  • Lastpage
    6677
  • Abstract
    The tracing of attacks and the reconstruction of attack scenarios are among the research fields that have been investigated these last years. In this context, several marking techniques have been proposed to traceback the attacker IP address or network. These schemes have shown limitations when dealing with the investigation of attacks since they are unable to reconstruct the attacker actions, and tolerate any form of missing traces or marks. In addition, these schemes are vulnerable to mark spoofing and altering. To deal with these limitations, we propose in this paper an outbound global marking scheme which uses a novel structure, called mark association, that holds enriched information about the intruder activity either at the network, system or storage level. The proposed scheme enables the monitoring of the intruder activity, the tracking of occurred events, the traceback of the attackers source addresses, in addition to the reconstruction of attack scenarios. The capabilities of the proposed scheme are illustrated through a distributed attack performed against the monitored environment.
  • Keywords
    IP networks; telecommunication traffic; IP address; attack scenarios; communication networks; global marking scheme; mark association; marking techniques; Context; Correlation; IP networks; Libraries; Monitoring; Security; dependency graph; investigation; mark association; storage;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Communications (ICC), 2012 IEEE International Conference on
  • Conference_Location
    Ottawa, ON
  • ISSN
    1550-3607
  • Print_ISBN
    978-1-4577-2052-9
  • Electronic_ISBN
    1550-3607
  • Type

    conf

  • DOI
    10.1109/ICC.2012.6364965
  • Filename
    6364965