An evaluation of connection characteristics for separating network attacks

TitleAn evaluation of connection characteristics for separating network attacks
Publication TypeJournal Articles
Year of Publication2009
AuthorsBerthier R, Cukier M
JournalInternational Journal of Security and Networks
Volume4
Issue1
Pagination110 - 124
Date Published2009/01/01/
Abstract

The goal of this paper is to evaluate the efficiency of connection characteristics to separate different attack families that target a single TCP port. Identifying the most relevant characteristics might allow statistically separating attack families without systematically using forensics. This study is based on a dataset collected over 117 days using a test-bed of two high interaction honeypots. The results indicated that to separate unsuccessful from successful attacks in malicious traffic: the number of bytes is a relevant characteristic; time-based characteristics are poor characteristics; using combinations of characteristics does not improve the efficiency of separating attacks.

URLhttp://dx.doi.org/10.1504/IJSN.2009.02343
DOI10.1504/IJSN.2009.02343