Worms could dodge Net traps

By Anne Broache, CNET News.com
Friday, August 05, 2005 11:40 AM

BALTIMORE--Future worms could evade a network of early-warning sensors hidden across the Internet unless countermeasures are taken, according to new research.

In a pair of papers presented at the Usenix Security Symposium here Thursday, computer scientists said would-be attackers can locate such sensors, which act as trip wires that detect unusual activity. That would permit nefarious activities to take place without detection.

Internet sensor networks, such as the University of Michigan's Internet Motion Sensor and the SANS Internet Storm Center, are groups of machines that monitor traffic across active networks and chunks of unused IP space. The sensor networks generate and publish statistical reports that permit an analyst to track the traffic, sniff out malicious activity and seek ways to combat it.

Just as surveillance cameras are sometimes hidden, the locations of the Internet sensors are kept secret. "If the set of sensors is known, a malicious attacker could avoid the sensors entirely or could overwhelm the sensors with errant data," a team of computer scientists from the University of Wisconsin wrote in its award-winning paper titled "Mapping Internet Sensors with Probe Response Attacks."

But the Wisconsin researchers discovered that the sensor maps furnish just enough information for someone to create an algorithm that can map the location of the sensors "even with reasonable constraint on bandwidth and resources," John Bethencourt, one of the paper's authors, said in his presentation.

All an attacker would have to do is throw packets of information at IP addresses and then check to see whether the activity showed up on the sensor reports. If it didn't, "we (could) safely assume the address was not monitored," Bethencourt said.

After running a simulated attack on the SANS Internet Storm Center's network and on randomly generated IP addresses, Bethencourt and his team found it would take less than a week, with high bandwidth, to uncover the identities of sensors in the SANS network and other similar networks.

With that new information, the attacker could continue to engage in suspicious behavior without being detected. "The results would be pretty severe," Bethencourt said.

"This is particularly worrisome in the case of worms," he added, since the sensors are often the first to detect that breed of Internet menace.

Japanese paper
Researchers from Japan came to a similar conclusion in a paper titled "Vulnerabilities of Passive Internet Threat Monitors." They noted that sensor attackers can identify the location of sensors without the aid of a "complete list of sensor addresses." They also devised several algorithms that managed to pinpoint the sensors "in surprisingly short time."

"We believe that we have found a new class of Internet threat," the researchers wrote, "because it does not pose a danger to the host systems themselves, but rather a danger to a metasystem that is intended to keep the host systems safe."

The threat could be diminished, both studies said, if the information in the networks' public reports was less detailed.

The Wisconsin researchers said current countermeasures, such as encryption and obscuring of IP addresses, simply aren't adequate. They suggested that the widespread adoption of IPv6, the next-generation Internet, could also help to curb attacks because of its longer IP addresses.

Yoichi Shinoda, who co-authored the Japanese study, emphasized in his presentation that because network sensors are the "sole" means of monitoring Internet background traffic, "we must protect them."


WORTHWHILE?

0

0 votes
Blog

Talkback 1 comments

I WANT FIND PASSWORD I SAY YOU NICK AND YOU GIVE ME PASSWORD OK!! NICK BRITNEY'S FAN AND SHE'S ICQ NUMBER 298-464-760
Posted by FARID on Saturday, August 13 2005 04:27 PM


Tech Jobs Now!

Search for your ideal tech job:

A look at the Terminal Services Manager in Windows Server 2008

Windows Server

Terminal Services Manager has been around for a while, but Microsoft made some changes to the utility in Windows Server 2008. Here's what you'll find.


Read more »



Open source blog reloaded!

Blog thumbnail

This is with great pleasure that this "little corner of the Web" is resuming activities through another member of the (now famous ;-)) Beijing Linux User Group (BLUG) doing the..... by Fred Muller

Read more »

Tags

  1. attack
  2. authentication and encryption
  3. blog
  4. data security
  5. e - mail
  6. google inc.
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. symantec corp.
  19. viruses and worms
  20. web