Automatically Determining a Network Reconnaissance Scope Using Passive Scanning Techniques

06/28/2021
by   Stefan Marksteiner, et al.
0

The starting point of securing a network is having a concise overview of it. As networks are becoming more and more complex both in general and with the introduction of IoT technology and their topological peculiarities in particular, this is increasingly difficult to achieve. Especially in cyber-physical environments, such as smart factories, gaining a reliable picture of the network can be, due to intertwining of a vast amount of devices and different protocols, a tedious task. Nevertheless, this work is necessary to conduct security audits, compare documentation with actual conditions or found vulnerabilities using an attacker's view, for all of which a reliable topology overview is pivotal. For security auditors, however, there might not much information, such as asset management access, be available beforehand, which is why this paper assumes network to audit as a complete black box. The goal is therefore to set security auditors in a condition of, without having any a priori knowledge at all, automatically gaining a topology oversight. This paper describes, in the context of a bigger system that uses active scanning to determine the network topology, an approach to automate the first steps of this procedure: passively scanning the network and determining the network's scope, as well as gaining a valid address to perform the active scanning. This allows for bootstrapping an automatic network discovery process without prior knowledge.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
04/06/2022

IoT-Scan: Network Reconnaissance for the Internet of Things

Network reconnaissance is a core networking and security procedure aimed...
research
04/08/2019

Efficient Passive ICS Device Discovery and Identification by MAC Address Correlation

Owing to a growing number of attacks, the assessment of Industrial Contr...
research
02/18/2023

Reproducing Random Forest Efficacy in Detecting Port Scanning

Port scanning is the process of attempting to connect to various network...
research
12/19/2020

Network Reconnaissance in IPv6-based Residential Broadband Networks

Network scanning has been a widely used technique to gather information ...
research
01/31/2023

Machine Learning and Port Scans: A Systematic Review

Port scanning is the process of attempting to connect to various network...
research
08/07/2020

Role-Based Deception in Enterprise Networks

Historically, enterprise network reconnaissance is an active process, of...

Please sign up or login with your details

Forgot password? Click here to reset