ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Worms dodge Internet sensors

Anen Broache CNET News.com

Published: 05 Aug 2005 10:45 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Future worms could evade a network of early-warning sensors hidden across the Internet unless countermeasures are taken, according to new research.

In a pair of papers presented at the Usenix Security Symposium in Baltimore, US on Thursday, computer scientists said would-be attackers can locate such sensors, which act as trip wires that detect unusual activity. That would permit nefarious activities to take place without detection.

Internet sensor networks, such as the University of Michigan's Internet Motion Sensor and the SANS Internet Storm Center, are groups of machines that monitor traffic across active networks and chunks of unused IP space. The sensor networks generate and publish statistical reports that permit an analyst to track the traffic, sniff out malicious activity and seek ways to combat it.

Locations of the Internet sensors are kept secret. "If the set of sensors is known, a malicious attacker could avoid the sensors entirely or could overwhelm the sensors with errant data," a team of computer scientists from the University of Wisconsin wrote in its award-winning paper titled "Mapping Internet Sensors with Probe Response Attacks."

But the Wisconsin researchers discovered that the sensor maps furnish just enough information for someone to create an algorithm that can map the location of the sensors "even with reasonable constraint on bandwidth and resources," John Bethencourt, one of the paper's authors, said in his presentation.

All an attacker would have to do is throw packets of information at IP addresses and then check to see whether the activity showed up on the sensor reports. If it didn't, "we (could) safely assume the address was not monitored," Bethencourt said.

After running a simulated attack on the SANS Internet Storm Center's network and on randomly generated IP addresses, Bethencourt and his team found it would take less than a week, with high bandwidth, to uncover the identities of sensors in the SANS network and other similar networks.

With that new information, the attacker could continue to engage in suspicious behavior without being detected. "The results would be pretty severe," Bethencourt said.

"This is particularly worrisome in the case of worms," he added, since the sensors are often the first to detect that breed of Internet menace.

Researchers from Japan came to a similar conclusion in a paper titled "Vulnerabilities of Passive Internet Threat Monitors." They noted that sensor attackers can identify the location of sensors without the aid of a "complete list of sensor addresses." They also devised several algorithms that managed to pinpoint the sensors "in surprisingly short time."

"We believe that we have found a new class of Internet threat," the researchers wrote, "because it does not pose a danger to the host systems themselves, but rather a danger to a metasystem that is intended to keep the host systems safe."

The threat could be diminished, both studies said, if the information in the networks' public reports was less detailed.

The Wisconsin researchers said current countermeasures, such as encryption and obscuring of IP addresses, simply aren't adequate. They suggested that the widespread adoption of IPv6, the next-generation Internet, could also help to curb attacks because of its longer IP addresses.

Yoichi Shinoda, who co-authored the Japanese study, emphasized in his presentation that because network sensors are the "sole" means of monitoring Internet background traffic, "we must protect them."

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Kyocera

Did you find this article useful?
48 out of 124 people found this useful


Full Talkback thread

0 comments


Related Jobs

Oracle DBA - Database Management Non-Live

Monitors database activity and ensures efficient access to data, working with data analysis and database design functions where appropriate. COMPANY ...

Strategic Business Analyst, Business Analyst, Planning, North Yorks.

Analysis - Structured Methodology (Pestle/Activity Mapping/Customer Needs Analysis) - Organisational Change - Business Analysis - Requirements ...

Server Architect - C# ASP.NET SQL - Redhill (Surrey) - 50k - 60k

They seek a Team Leader, application developer and architect for their recently created and growing web services activity. This activity is being ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Biometric devices. Do you need one?

When saying “biometrics” I am not thinking about law enforcement, AFIS systems, national ID and visa projects. I first think about personal solutions that will make my life easier.... More

1 comment

Barracuda launches counter-suit agains...

Court cases are never pleasant or simple. The ongoing battle between security companies Trend Micro and Barracuda Networks took a new twist on Wednesday, when Barracuda launched a counter-suit... More

Post a comment

Mobile Speed Demon: Wireless Surpasses...

Mobile Speed Demon: Wireless Surpasses Landline Author: Eric Everson, Founder MyMobiSafe.com As I look around my house and throughout my network of friends, I instantly realize... More

Post a comment