• DocumentCode
    677232
  • Title

    Improving accuracy of applications fingerprinting on local networks using NMAP-AMAP-ETTERCAP as a hybrid framework

  • Author

    Ghanem, Waheed Ali H. M. ; Belaton, Bahari

  • Author_Institution
    Sch. of Comput. Sci., Univ. Sains Malaysia (USM), Minden, Malaysia
  • fYear
    2013
  • fDate
    Nov. 29 2013-Dec. 1 2013
  • Firstpage
    403
  • Lastpage
    407
  • Abstract
    The process of detecting running software on remote hosts, is generally known as fingerprinting. Fingerprinting process is performed as step before the attack stage on the remote host. There are two types of fingerprinting; active and passive fingerprinting. However, each type encountered limitation when implemented separately in networks, and their inability to provide accurate information about the host services/applications. The main objective of this paper is to propose possibility of enhancing the detection process of the host profiling, applications/ services fingerprinting and the methods of host identification. Herein, we perform network host profiling by identifying different services/ applications that were running on the host. More so, we exploit sophisticated process of application layer protocol payloads by active and passive fingerprinting tools. Besides, we attempt to add a layer of correctness into these tool results, by building a new database of signatures which is derived from these results. The new signature database can be tested either exactly or through approximate fuzzy matching. The experiment results give a better accurate output compare to the base tools alone.
  • Keywords
    fuzzy set theory; local area networks; protocols; LAN; NMAP-AMAP-ETTERCAP tools; active fingerprinting; application layer protocol; approximate fuzzy matching; attack stage; local area networks; passive fingerprinting; remote host; signature database; Accuracy; Approximation algorithms; Databases; Fingerprint recognition; Operating systems; Ports (Computers); Protocols; active and passive fingerprinting; fingerprinting; fuzzy; matching; remote services/applications detection;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Control System, Computing and Engineering (ICCSCE), 2013 IEEE International Conference on
  • Conference_Location
    Mindeb
  • Print_ISBN
    978-1-4799-1506-4
  • Type

    conf

  • DOI
    10.1109/ICCSCE.2013.6719998
  • Filename
    6719998