Invention Grant
- Patent Title: System and method for connection fingerprint generation and stepping-stone traceback based on netflow
-
Application No.: US15345354Application Date: 2016-11-07
-
Publication No.: US10264004B2Publication Date: 2019-04-16
- Inventor: Jung Tae Kim , Koo Hong Kang , Ik Kyun Kim
- Applicant: ELECTRONICS AND TELECOMMUNICATIONS RESEARCH INSTITUTE
- Applicant Address: KR Daejeon
- Assignee: ELECTRONICS AND TELECOMMUNICATIONS RESEARCH INSTITUTE
- Current Assignee: ELECTRONICS AND TELECOMMUNICATIONS RESEARCH INSTITUTE
- Current Assignee Address: KR Daejeon
- Priority: KR10-2015-0156952 20151109; KR10-2016-0052154 20160428
- Main IPC: H04L12/26
- IPC: H04L12/26 ; H04L29/06

Abstract:
The method for tracking a cyber hacking is provided. The method of connection fingerprint generation and stepping-stone traceback based on NetFlow includes receiving a traceback request including IP packet attribute information of a victim and an attacker which corresponds to a target connection that is the last connection on a connection chain, generating a fingerprint for an associated connection based on the IP packet attribute information and requesting a NetFlow collector for relevant information, detecting a stepping-stone connection to the target connection which is generated at the time of generation of the fingerprint and instructing to check whether sorted candidate connections are present on the same connection chain as the target connection, and determining an order of the candidate connections based on an attacker host when the candidate connections are determined to be present on the same connection chain as the target connection.
Public/Granted literature
- US20170134413A1 SYSTEM AND METHOD FOR CONNECTION FINGERPRINT GENERATION AND STEPPING-STONE TRACEBACK BASED ON NETFLOW Public/Granted day:2017-05-11
Information query