Title :
Improving accuracy of applications fingerprinting on local networks using NMAP-AMAP-ETTERCAP as a hybrid framework
Author :
Ghanem, Waheed Ali H. M. ; Belaton, Bahari
Author_Institution :
Sch. of Comput. Sci., Univ. Sains Malaysia (USM), Minden, Malaysia
fDate :
Nov. 29 2013-Dec. 1 2013
Abstract :
The process of detecting running software on remote hosts, is generally known as fingerprinting. Fingerprinting process is performed as step before the attack stage on the remote host. There are two types of fingerprinting; active and passive fingerprinting. However, each type encountered limitation when implemented separately in networks, and their inability to provide accurate information about the host services/applications. The main objective of this paper is to propose possibility of enhancing the detection process of the host profiling, applications/ services fingerprinting and the methods of host identification. Herein, we perform network host profiling by identifying different services/ applications that were running on the host. More so, we exploit sophisticated process of application layer protocol payloads by active and passive fingerprinting tools. Besides, we attempt to add a layer of correctness into these tool results, by building a new database of signatures which is derived from these results. The new signature database can be tested either exactly or through approximate fuzzy matching. The experiment results give a better accurate output compare to the base tools alone.
Keywords :
fuzzy set theory; local area networks; protocols; LAN; NMAP-AMAP-ETTERCAP tools; active fingerprinting; application layer protocol; approximate fuzzy matching; attack stage; local area networks; passive fingerprinting; remote host; signature database; Accuracy; Approximation algorithms; Databases; Fingerprint recognition; Operating systems; Ports (Computers); Protocols; active and passive fingerprinting; fingerprinting; fuzzy; matching; remote services/applications detection;
Conference_Titel :
Control System, Computing and Engineering (ICCSCE), 2013 IEEE International Conference on
Conference_Location :
Mindeb
Print_ISBN :
978-1-4799-1506-4
DOI :
10.1109/ICCSCE.2013.6719998