In this digital era, safeguarding internet resources in cyberspace is vital. They are frequently targeted by attackers because of their prevalence and 24 × 7 availability. These cyber-attacks aim to compromise the integrity, confidentiality, and accessibility of data and systems. Exploitation of internet resources is performed in multiple stages. The initial phase of an attack is reconnaissance, by which the attacker uses highly advanced, automated scanning tools to scan perimeter devices and gather information about the target resources, identify vulnerabilities to plan their attack strategies. These reconnaissance attacks are typically covert, discreet, and challenging to detect using conventional intrusion detection systems. Identifying and countering reconnaissance attacks in their early stages can significantly minimize the attack surface and enhance network security. Reconnaissance attacks can lead to unusual fluctuations in the volume and size of incoming and outgoing packets. The intention of this work is to pinpoint unusual traffic patterns and illustrate their potential in detecting and preventing reconnaissance scans at an early stage. By employing Machine-Learning (ML) algorithms on captured packet and analyzing security logs from perimeter devices, the occurrence of extensive scanning can be detected. Traffic characteristics-based features have been identified and extracted to train ML models. The proposed system utilizes the decisions provided by the ML model and IPs identified through log processing to implement dynamic access policy rules on firewalls and routers. This prevents scanning IPs from accessing organizational internet-facing resources. The Random Forest algorithm was used to train the Machine Learning models alongside other algorithms, resulting in an accuracy rate of 94.62%. The system has identified and blocked more than 1000 attacking IPs in the last six months which is a significant enhancement in organizational network security posture.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Comprehensive Approach to Detect and Prevent Reconnaissance Attack

  • S. Chaudhari,
  • V. K. Maurya,
  • S. S. Tomar,
  • A. Rajan

摘要

In this digital era, safeguarding internet resources in cyberspace is vital. They are frequently targeted by attackers because of their prevalence and 24 × 7 availability. These cyber-attacks aim to compromise the integrity, confidentiality, and accessibility of data and systems. Exploitation of internet resources is performed in multiple stages. The initial phase of an attack is reconnaissance, by which the attacker uses highly advanced, automated scanning tools to scan perimeter devices and gather information about the target resources, identify vulnerabilities to plan their attack strategies. These reconnaissance attacks are typically covert, discreet, and challenging to detect using conventional intrusion detection systems. Identifying and countering reconnaissance attacks in their early stages can significantly minimize the attack surface and enhance network security. Reconnaissance attacks can lead to unusual fluctuations in the volume and size of incoming and outgoing packets. The intention of this work is to pinpoint unusual traffic patterns and illustrate their potential in detecting and preventing reconnaissance scans at an early stage. By employing Machine-Learning (ML) algorithms on captured packet and analyzing security logs from perimeter devices, the occurrence of extensive scanning can be detected. Traffic characteristics-based features have been identified and extracted to train ML models. The proposed system utilizes the decisions provided by the ML model and IPs identified through log processing to implement dynamic access policy rules on firewalls and routers. This prevents scanning IPs from accessing organizational internet-facing resources. The Random Forest algorithm was used to train the Machine Learning models alongside other algorithms, resulting in an accuracy rate of 94.62%. The system has identified and blocked more than 1000 attacking IPs in the last six months which is a significant enhancement in organizational network security posture.