arrow
返回

Two-Phased Method for Detecting Evasive Network Attack Channels

delete2014-08-01
delete0
PRE
AI
Z
Zigang Cao
G
Gang Xiong *
赵勇 封面图
赵勇 (Yong Zhao)
郭力 封面图
郭力 (Li Guo)
B
Binxing Fang
DOI:10.1109/CC.2014.6911087delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
With the rapid developments of information technology, various industries become much more dependent on networks. Driven by economic interests and the game between countries reflected by growing cyberspace confrontations, evasive network attacks on information infrastructures with high-tech, high concealment and long-term sustainability become severe threats to national security. In this paper, we propose a novel two-phased method for the detection of evasive network attacks which exploit or pretend to be common legal encryption services in order to escape security inspection. Malicious communications which camouflage themselves as legal encryption application are identified in the SSL1 session structure verification phase firstly, and then by server-side X.509 certificate based anomaly detection, suspicious attack behaviors are further distinguished effectively. Experiment results show that our method is very useful for detecting the network activities of certain unknown threats or new malwares. Besides, the proposed method can be applied to other similar services easily.
Keyword:
evasive network attacks
encryption
SSL
X.509 certificate
anomaly detection
AI总结

AI总结

对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。

期刊

China Communications 封面图
China Communications
IF:
3.1
论文数:
1.9K
被引数:
5.0K

机构

B
beijing university of posts & telecommunications
学者数:
1.4W
论文数: 1.2W
被引数: 9
C
chinese academy of sciences
学者数:
56.7W
论文数: 45.0W
被引数: 704
引用论文

引用论文

暂无论文信息