DocumentCode :
3348952
Title :
A Self-Healing, Self-Protecting Collaborative Intrusion Detection Architecture to Trace-Back Fast-Flux Phishing Domains
Author :
Zhou, Chenfeng Vincent ; Leckie, Christopher ; Karunasekera, Shanika ; Peng, Tao
Author_Institution :
Dept. of Comput. Sci. & Software Eng., Melbourne Univ., Melbourne, VIC
fYear :
2008
fDate :
7-11 April 2008
Firstpage :
321
Lastpage :
327
Abstract :
Millions of users divulge their personal information on phishing web sites, which causes over a billion dollars loss every year. Phishing domain take-down is the most promising approach to address this security issue, since there will be nothing there for a misled user to see if the fraudulent website has been removed completely. A key part of the take-down procedure is phishing hosting system trace-back. Traditional phishing hosting machines can be identified relatively quickly by their public DNS name or directly if their IP address is embedded within spam email. However, a newer architectural innovation known as fast-flux networks uses a pool of compromised machines to hide the phishing website hosting system, which makes phishing website trace-back almost impractical. We propose a decentralized collaborative intrusion detection approach to address this defense challenge, which is based on a collaborative intrusion detection system (CIDS) architecture. The participating detection systems are from different ISPs, which allows the fast-flux machines to be monitored. The suspicious communication pattern of fast- flux machines are correlated across different ISPs in a multistage manner, to trace-back the actual phishing website hosting machine. The architecture is scalable and self-healing through its use of a structured peer-to-peer network, and also enables the participants to be self-protecting. The communication is loosely coupled by a publish/subscribe mechanism. Our evaluation results show that our proposed decentralized CIDS is more effective than a fully centralized system.
Keywords :
Internet; Web sites; groupware; peer-to-peer computing; security of data; telecommunication security; IP address; Internet service provider; Web sites; fast-flux network; peer-to-peer network; self-healing collaborative intrusion detection architecture; self-protecting collaborative intrusion detection architecture; trace-back fast-flux phishing domain; Collaboration; Collaborative software; Computer architecture; Computer science; Gold; Government; Intrusion detection; Iron; Laboratories; Software engineering;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Network Operations and Management Symposium Workshops, 2008. NOMS Workshops 2008. IEEE
Conference_Location :
Salvador da Bahia
Print_ISBN :
978-1-4244-2067-4
Type :
conf
DOI :
10.1109/NOMSW.2007.50
Filename :
4509966
Link To Document :
بازگشت