Research and implementation of active intrusion tracing
Tian Zhi · Applied science and technology · 2003
We inquired into how to trace the intruders who most likely utilize chained connections to hide their origin,and presented a novel active intrusion tracing framework: Watermark Tracing System(WTS).WTS is in sleepy mode when no intrusion is detected.Once intrusion is coming,WTS is waken up to inject watermark into the connection and collect the information in the path of connection from the router.By integrating the watermark technology and active tracing protocol,the system can effectively trace the hacker origin who uses telnet or rlogin to create chained connections.