Digesting Network Traffic for Forensic Investigation Using Digital Signal Processing Techniques

10/04/2019
by   S. Mohammad Hosseini, et al.
0

One of the most important practices of cybercrime investigations is to search a network traffic history for an excerpt of traffic, such as the disclosed information of an organization or a worm signature. In post-mortem investigations, criminals and targets are detected by attributing the excerpt to payloads of traffic flows. Since it is impossible to store the high volume of data related to long-term traffic history, payload attribution systems (PAS) based on storing a compact digest of traffic using Bloom filters have been presented in the literature. In these systems, querying the stored digest for an excerpt results in a low number of suspects instead of certain criminals. In this paper, we present a different PAS which is based on simple and widespread digital signal processing techniques. Our traffic digesting scheme has been inspired by DSP-based compression algorithms. The proposed payload attribution system, named DSPAS, not only results in a low false positive rate but also outperforms previous schemes in response to wildcard queries which are essentially applicable for complex excerpts such as the signature of polymorphic worms. Our theoretical analysis and practical evaluations show that DSPAS results in a significantly lower false positive rate and also a lower processing time for wildcard queries in comparison to previous works. Moreover, our PAS can prevent a malicious insider from evading the PAS by its ability to find strings similar to a queried excerpt.

READ FULL TEXT
research
06/12/2019

An Effective Payload Attribution Scheme for Cybercriminal Detection Using Compressed Bitmap Index Tables and Traffic Downsampling

Payload attribution systems (PAS) are one of the most important tools of...
research
08/05/2020

MORTON: Detection of Malicious Routines in Large-Scale DNS Traffic

In this paper, we present MORTON, a system that identifies compromised e...
research
11/05/2017

Bloom Filters, Adaptivity, and the Dictionary Problem

The Bloom filter---or, more generally, an approximate membership query d...
research
05/23/2019

COBS: a Compact Bit-Sliced Signature Index

We present COBS, a compact bit-sliced signature index, which is a cross-...
research
04/17/2018

Fast Flux Detection via Data Mining on Passive DNS Traffic

In the last decade, the use of fast flux technique has become establishe...
research
08/21/2021

Deep Representation of Imbalanced Spatio-temporal Traffic Flow Data for Traffic Accident Detection

Automatic detection of traffic accidents has a crucial effect on improvi...

Please sign up or login with your details

Forgot password? Click here to reset