首页    期刊浏览 2024年10月06日 星期日
登录注册

文章基本信息

  • 标题:Modeling of Cyber Reconnaissance through the Analysis of Hidden IP based Web Access logs
  • 作者:Wanju Kim ; Changwook Park ; Soojin Lee
  • 期刊名称:Journal of Security Engineering
  • 印刷版ISSN:1738-7531
  • 出版年度:2016
  • 卷号:13
  • 期号:3
  • 页码:205-220
  • DOI:10.14257/jse.2016.06.04
  • 出版社:SERSC
  • 摘要:Recently, cyber attacks are constantly increasing, and the recognition of cyber attacks beforehand hasrisen in prominence for the rapid response. However, since the attackers generally use hidden IP via VPNor Proxy to hide their actions and origins, it is not easy to recognize their attacks in advance. To addressthis problem, in this paper, we propose an approach to extract the cyber reconnaissance activity pattern ofthe attacker who uses hidden IP. We first collected the web logs that generated by the attackers who hadaccessed certain web pages using hidden IP. Then we analysed the collected web logs based onSNA(Social Network Analysis) and K-means clustering algorithm, and extracted some differentiated behaviorpatterns. We also compare the extracted behavior patterns and the normal behavior patterns of general webusers to verify the differences of them.
  • 关键词:Cyber Warfare; Hidden IP; Cyber Reconnaissance; SNA(Social Network Analysis); Clustering; K-means
Loading...
联系我们|关于我们|网站声明
国家哲学社会科学文献中心版权所有