DocumentCode :
3705249
Title :
A deception based approach for defeating OS and service fingerprinting
Author :
Massimiliano Albanese;Ermanno Battista;Sushil Jajodia
Author_Institution :
Center for Secure Information Systems, George Mason University, Fairfax, VA 22030, USA
fYear :
2015
Firstpage :
317
Lastpage :
325
Abstract :
Cyber attacks are typically preceded by a reconnaissance phase in which attackers aim at collecting critical information about the target system, including information about network topology, services, operating systems, and unpatched vulnerabilities. Specifically, operating system fingerprinting aims at determining the operating system of a remote host in either a passive way, through sniffing and traffic analysis, or an active way, through probing. Similarly, service fingerprinting aims at determining what services are running on a remote host. In this paper, we propose an approach to defeat an attacker´s fingerprinting effort through deception. To defeat OS fingerprinting, we manipulate outgoing traffic so that it resembles traffic generated by a host with a different operating system. Similarly, to defeat service fingerprinting, we modify the service banner by intercepting and manipulating certain packets before they leave the host or network. Experimental results show that our approach can efficiently and effectively deceive an attacker.
Keywords :
"Probes","Operating systems","IP networks","Ports (Computers)","Standards","Fingerprint recognition","Protocols"
Publisher :
ieee
Conference_Titel :
Communications and Network Security (CNS), 2015 IEEE Conference on
Type :
conf
DOI :
10.1109/CNS.2015.7346842
Filename :
7346842
Link To Document :
بازگشت