首页> 外文期刊>ACM Transaction on Information and System Security >The Session Token Protocol for Forensics and Traceback
【24h】

The Session Token Protocol for Forensics and Traceback

机译:用于取证和追溯的会话令牌协议

获取原文
获取原文并翻译 | 示例

摘要

In this paper we present the Session Token Protocol (STOP), a new protocol that can assist in the forensic analysis of a computer involved in malicious network activity. It has been designed to help automate the process of tracing attackers who log on to a series of hosts to hide their identity. STOP utilizes the Identification Protocol infrastructure, improving both its capabilities and user privacy. On request, the STOP protocol saves user-level and application-level data associated with a particular TCP connection and returns a random token specifically related to that session. The saved data are not revealed to the requester unless the token is returned to the local administrator, who verifies the legitimacy of the need for the release of information. The protocol supports recursive traceback requests to gather information about the entire path of a connection. This allows an incident investigator to trace attackers to their home systems, but does not violate the privacy of normal users. This paper details the new protocol and presents implementation and performance results.
机译:在本文中,我们介绍了会话令牌协议(Session Token Protocol,STOP),这是一种新协议,可以协助对参与恶意网络活动的计算机进行取证分析。它旨在帮助自动跟踪跟踪登录到一系列主机以隐藏其身份的攻击者的过程。 STOP利用身份验证协议基础结构,同时提高了其功能和用户隐私。根据请求,STOP协议将保存与特定TCP连接关联的用户级和应用程序级数据,并返回与该会话特别相关的随机令牌。除非将令牌返回给本地管理员,该管理员将验证发布信息的合法性,否则保存的数据不会透露给请求者。该协议支持递归回溯请求,以收集有关连接整个路径的信息。这使事件调查者可以将攻击者追踪到其家庭系统,但不会侵犯普通用户的隐私。本文详细介绍了新协议,并给出了实现和性能结果。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号