A clustering-partitioning algorithm to find TCP packet round-trip time for intrusion detection

Jianhua Yang, Shou‐Hsuan Stephen Huang, M.D. Wan · 2006

An effective approach for detecting stepping-stone intrusion is to estimate the number of hosts compromised through estimating the length of a connection chain. This can be done by studying the changes in TCP packet round-trip time. In this paper, we propose a new algorithm by using maximum-minimum distance clustering and partitioning method to find the round-trip time from the time-stamps of TCP send and echo packets. Previous algorithms produce either good results on very few packets, or poor results on many packets. This method gives us better round-trip time and more packets than other algorithms proposed in the past.

Read the paper · More papers on PaperTik