Robust network-based attack attribution through probabilistic watermarking of packet flows
Xinyuan Wang, Douglas S. Reeves, Peng Ning, Fang Feng · NCSU Libraries Repository (North Carolina State University Libraries) · 2005
Network based intruders often stage their attacks through intermediate "stepping stones" to conceal their identity and origin.To identify attackers behind stepping stones, it is necessary to be able to correlate encrypted connections through stepping stones, even if those connections are perturbed in timing by the intruder to prevent traceability.The active watermarking based correlation approach [20] has show advantages over some passive timing based correlation in the presence of active timing perturbation by the attacker.However, the watermarking scheme presented there, based on timing quantization, does not guarantee even adjustment of time over multiple selected packets at real-time.To make the watermark embedding less noticeable to the attacker, it is desirable to adjust the timing evenly over the selected packets.In this paper, we propose a novel probabilistic watermarking correlation scheme that has guaranteed even timing adjustment over multiple selected packets at real-time.This method has all of the theoretical strength of the provable upper bounds and accurate approximation of the previous quantization based watermarking method [20].The probabilistic watermarking method essentially trades the watermark embedding success rate for the even time adjustment.Analytical results show that the impact of probabilistic watermarking on watermark detection is equivalent to an additional random delay by the attacker on an otherwise 100% successful watermark embedding scheme.We also identify the provable bounds and accurate tradeoffs between the achievable correlation effectiveness and the defining characteristics of the random timing perturbation.Unlike most previous correlation approaches, our probabilistic watermarking correlation makes no assumptions about the distribution of original inter-packet timing or adversary's random timing perturbation and it applies to arbitrarily distributed timing perturbation over packet flows with arbitrarily distributed inter-packet timing.Our analytical bounds and tradeoff model hold as long as the random timing perturbation by adversary is bounded.Analytical and experimental results show that the probabilistic watermarking is substantially more robust against random timing perturbations than previous quantization based watermarking, while having virtually the same correlation true positive rate under small timing perturbation.