@article{ART001992791},
author={Koohong Kang},
title={A Brute-force Technique for the Stepping Stone Self-Diagnosis of Interactive Services on Linux Servers},
journal={Journal of The Korea Society of Computer and Information},
issn={1598-849X},
year={2015},
volume={20},
number={5},
pages={41-51}
TY - JOUR
AU - Koohong Kang
TI - A Brute-force Technique for the Stepping Stone Self-Diagnosis of Interactive Services on Linux Servers
JO - Journal of The Korea Society of Computer and Information
PY - 2015
VL - 20
IS - 5
PB - The Korean Society Of Computer And Information
SP - 41
EP - 51
SN - 1598-849X
AB - In order to hide their identities, intruders on the Internet often attack targets indirectly by staging their attacks through intermediate hosts known as stepping stones. In this paper, we propose a brute-force technique to detect the stepping stone behavior on a Linux server where some shell processes remotely logged into using interactive services are trying to connect other hosts using the same interactive services such as Telnet, Secure Shell, and rlogin. The proposed scheme can provide an absolute solution even for the encrypted connections using SSH because it traces the system calls of all processes concerned with the interactive service daemon and their child processes. We also implement the proposed technique on a CentOS 6.5 x86_64 environment by the ptrace system call and a simple shell script using strace utility.
Finally the experimental results show that the proposed scheme works perfectly under test scenarios.
KW - Stepping stone;Trace-back;Connection chain
DO -
UR -
ER -
Koohong Kang. (2015). A Brute-force Technique for the Stepping Stone Self-Diagnosis of Interactive Services on Linux Servers. Journal of The Korea Society of Computer and Information, 20(5), 41-51.
Koohong Kang. 2015, "A Brute-force Technique for the Stepping Stone Self-Diagnosis of Interactive Services on Linux Servers", Journal of The Korea Society of Computer and Information, vol.20, no.5 pp.41-51.
Koohong Kang "A Brute-force Technique for the Stepping Stone Self-Diagnosis of Interactive Services on Linux Servers" Journal of The Korea Society of Computer and Information 20.5 pp.41-51 (2015) : 41.
Koohong Kang. A Brute-force Technique for the Stepping Stone Self-Diagnosis of Interactive Services on Linux Servers. 2015; 20(5), 41-51.
Koohong Kang. "A Brute-force Technique for the Stepping Stone Self-Diagnosis of Interactive Services on Linux Servers" Journal of The Korea Society of Computer and Information 20, no.5 (2015) : 41-51.
Koohong Kang. A Brute-force Technique for the Stepping Stone Self-Diagnosis of Interactive Services on Linux Servers. Journal of The Korea Society of Computer and Information, 20(5), 41-51.
Koohong Kang. A Brute-force Technique for the Stepping Stone Self-Diagnosis of Interactive Services on Linux Servers. Journal of The Korea Society of Computer and Information. 2015; 20(5) 41-51.
Koohong Kang. A Brute-force Technique for the Stepping Stone Self-Diagnosis of Interactive Services on Linux Servers. 2015; 20(5), 41-51.
Koohong Kang. "A Brute-force Technique for the Stepping Stone Self-Diagnosis of Interactive Services on Linux Servers" Journal of The Korea Society of Computer and Information 20, no.5 (2015) : 41-51.