8002824266

8002824266



16 Bartosz Bielski, Przemysław Klęsk

broad networks. Moreover, it can cause some network devices to stop servicing. Passive fingerprinting hase nonę of the flaws mentioned above.

16 Bartosz Bielski, Przemysław Klęsk

Application


Application


Transport


Transport


HTTP

FTP

Soc

kets

TCP

UDP

ICMP IB '

IP ARP


Network Interface


Physical



Figurę 1. OSI and TCP/IP stack

(source: http://tutorials.beginners.co.uk/introducing-tcp-ip.htm?p=2)

Passive fingerprinting is a method of recognizing operating systems based only on the packet traffic which is already transmitted. There is no need to send extra packets to remote host, because all the packets may be used to identify attacker or any person that is doing a security audit.

A main goal of this research is to determine how accurately remote operating Systems can be detected using passive fingerprinting by means of neural networks and induction of decision rules. Other goal is to evaluate the fingerprinting on some user-modified TCP/IP stacks on which current recognition tools fail to work and determine how well neural networks can identify operating systems that were not in the training set.

2. Passive OS fingerprinting - existing Solutions

Based on our observations, which were confirmed by some of earlier researches [3], we can say that currently existing fingerprinting tools are mostly: rule based (very sim-ple rules) or nearest neighbour implementation (usually 1-NN). Using such approach there is no way to accurately fingerprint operating systems having any modifications that were not included in the fingerprinting database of the systems. On the other hand, there is no way to include all such information in the database because of the variety of possible modifications.



Wyszukiwarka

Podobne podstrony:
18 Bartosz Bielski, Przemysław Klęsk Table 1. Operating systems classes Pos. OS class Number of
20 Bartosz Bielski, Przemysław Klęsk4.1. Greedy induction of decision rules Say we want to find all
98 Bartosz Ziółko, Jakub Gałka, Mariusz Ziółko language. It can also be used in several speech proce
Passive operating system fingerprinting using neural networks and induction of decision rules Bartos
obraz5 (16) zamwiacze chorób i odwracacze klęsk elementarnych są ludźmi niebezpiecznymi, gdyż primo
obraz5 (16) zamwiacze chorób i odwracacze klęsk elementarnych są ludźmi niebezpiecznymi, gdyż primo
dr Przemysław Kubiak Piwowarski Bartosz dr Przemysław Kubiak Paciorek Bartłomiej dr
■ LUDZIE UCZELNI Habilitacja Przemysław Klęsk komisji habilitacyjnej odbyło się w czerwcu 2012 r. i
obraz5 (16) zamwiacze chorób i odwracacze klęsk elementarnych są ludźmi niebezpiecznymi, gdyż primo
16 Economics and Eiwironment 4(51) • 2014Ecosystem services in rural areas A separate session was de
Cisco 640-822 Interconnecting Cisco Networking Devices Part 1 Q&A with explanations Version
Sieci komputerowe .10 e)    sieć radiowa (Radio Network) - jest to sieć bezprzewodowa
Projekt ICHNOS PLUS, lnnovation and CHange: NetWork of One-stop Shops for Business - PLUS w ramach I
Sieć radiowa •    (Radio NetWork) - jest to sieć bezprzewodowa, w której medium

więcej podobnych podstron