Hybrid Incident Response Digital Traceback Technique in Network-Based Intrusion Source Detection

Ogwueleka Francisca Nonyelum, Okoye Martina Nonye · SSRN Electronic Journal · 2016

The proposed system called hybrid incident response digital traceback technique combines the digital forensic techniques and fusion-based IP traceback technology, which was used in identifying the source of network-based intrusion faster with a distinct alert. The digital forensic techniques and fusion-based IP traceback technology identified the source of network-based intrusion faster by tracing back to the root of the attack in an automated way. In the proposed system, 100 IP addresses and services were accessed on the network, Self-Organizing Map (SOM) detected 11 intrusions (packets with wrong IP addresses and services), while 89 packets were correct IP addresses and services. The network administrator applied the hybrid incident response digital traceback technique in order to detect the attack source faster once the attack is detected by SOM. Finally, the alert system alerts the administrator on the source of intrusion. The proposed system suggested very good performance for intrusion source detection.

Read the paper · More papers on PaperTik