Anti-Hacking White Papers
Finding a Connection Chain for Tracing Intruders
Overview
Intruders usually log in through a chain of multiple computer systems to hide their origins before breaking into their targets, which makes tracing difficult. In this paper we present a method to find the connection chain of an intruder for tracing back to the origin. We focus on telnet and rlogin as interactive applications intruders use to log in through hosts.
The method involves setting up packet monitors at as many traffic points as possible on the Internet to record the activities of intruders at the packet level. When a host is compromised and used as a step-through host to access another host, we compare the packet logs of the intruder at that host to logs we have recorded all over the Internet to find the closest match.
| Publisher | Silicon Defense | File Format | PDF, requires Acrobat Rdr 5 |
|---|---|---|---|
| Date Published | October 2000 | Downloads | 1 |
| Format | White Papers | ||
| Topics | |||



