Toward a Robust Method of Presenting a Rich, Interconnected Deceptive Network Topology

Abstract

Every day, adversaries bombard Department of Defense computer networks with scanning traffic in order to gather information about the target network. This reconnaissance is typically a precursor to attacks designed to access data, exfiltrate information, or plant malware in order to gain a military advantage. One specific reconnaissance tool, traceroute, is used to map the network topology of a target network. We implement an active network defense tool, dubbed DeTracer, that seeks to thwart network mapping attacks through the use of deception. We deploy DeTracer in several environments, including the Internet, to demonstrate that an attacker attempting to map a target network using traceroute probes can be presented with a false network topology of the defender s choosing. Our experiments show that a defender can present an adversary with a credible false network topology. We are able to deceive all types of incoming traceroute probes, present a complex false network topology on a per source and destination basis, and deploy our deception scheme without disrupting service to the real production infrastructure on our network.

Open PDF

Document Details

Document Type
Technical Report
Publication Date
Mar 01, 2015
Accession Number
ADA626655

Entities

People

  • Austin West

Organizations

  • Naval Postgraduate School

Tags

Communities of Interest

  • Cyber
  • Electronic Warfare
  • Energy and Power Technologies

DTIC Thesaurus Topics

  • Communication Systems
  • Computer Networks
  • Computer Science
  • Computing Devices
  • Cyberspace
  • Data Links
  • Department Of Homeland Security
  • Earth-To-Space Weapons
  • Homeland Security
  • Information Systems
  • Infrastructure
  • Internet
  • Network Protocols
  • Network Science
  • Network Topology
  • Operating Systems
  • Routing Protocols

Fields of Study

  • Computer science

Readers

  • Computer Networking
  • Cybersecurity.
  • Sensor Fusion and Tracking Systems.

Technology Areas

  • Cyber