Watch Your Step! Detecting Stepping Stones in Programmable Networks

Research output: Chapter in Book/Report/Conference proceedingConference contributionScientificpeer-review

Researchers

Research units

  • Linköping University

Abstract

Hackers hide behind compromised intermediate hosts and pose advanced persistent threats (APTs). The compromised hosts are used as stepping stones to launch real attacks, as is evident from an incident that shook the world in 2016 - Panama Papers Leak. The major attack would not go unnoticed if the compromised stepping stone, in this case an email server, could be identified in time. In this paper, we explore how today's programmable networks could be retrofitted with effective stepping stone detection mechanisms to correlate flows. We share initial results to prove that such a setup exists. Lastly, we analyze scalability issues associated with the setup and explore recent developments in network monitoring which have potential to address these issues.

Details

Original languageEnglish
Title of host publication2019 IEEE International Conference on Communications, ICC 2019 - Proceedings
Publication statusPublished - 1 May 2019
MoE publication typeA4 Article in a conference publication
EventIEEE International Conference on Communications - Shanghai, China
Duration: 20 May 201924 May 2019

Publication series

NameIEEE International Conference on Communications
PublisherIEEE
Volume2019-May
ISSN (Print)1550-3607

Conference

ConferenceIEEE International Conference on Communications
Abbreviated titleICC
CountryChina
CityShanghai
Period20/05/201924/05/2019

ID: 39065232