TY - GEN
T1 - Watch Your Step! Detecting Stepping Stones in Programmable Networks
AU - Bhattacherjee, Debopam
AU - Gurtov, Andrei
AU - Aura, Tuomas
PY - 2019/5/1
Y1 - 2019/5/1
N2 - Hackers hide behind compromised intermediate hosts and pose advanced persistent threats (APTs). The compromised hosts are used as stepping stones to launch real attacks, as is evident from an incident that shook the world in 2016 - Panama Papers Leak. The major attack would not go unnoticed if the compromised stepping stone, in this case an email server, could be identified in time. In this paper, we explore how today's programmable networks could be retrofitted with effective stepping stone detection mechanisms to correlate flows. We share initial results to prove that such a setup exists. Lastly, we analyze scalability issues associated with the setup and explore recent developments in network monitoring which have potential to address these issues.
AB - Hackers hide behind compromised intermediate hosts and pose advanced persistent threats (APTs). The compromised hosts are used as stepping stones to launch real attacks, as is evident from an incident that shook the world in 2016 - Panama Papers Leak. The major attack would not go unnoticed if the compromised stepping stone, in this case an email server, could be identified in time. In this paper, we explore how today's programmable networks could be retrofitted with effective stepping stone detection mechanisms to correlate flows. We share initial results to prove that such a setup exists. Lastly, we analyze scalability issues associated with the setup and explore recent developments in network monitoring which have potential to address these issues.
UR - http://www.scopus.com/inward/record.url?scp=85070221544&partnerID=8YFLogxK
U2 - 10.1109/ICC.2019.8761731
DO - 10.1109/ICC.2019.8761731
M3 - Conference contribution
AN - SCOPUS:85070221544
T3 - IEEE International Conference on Communications
BT - 2019 IEEE International Conference on Communications, ICC 2019 - Proceedings
PB - IEEE
T2 - IEEE International Conference on Communications
Y2 - 20 May 2019 through 24 May 2019
ER -