FILE DETECTION ON NETWORK TRAFFIC USING APPROXIMATE MATCHING

被引:0
|
作者
Breitinger, Frank [1 ]
Baggili, Ibrahim [1 ]
机构
[1] Univ New Haven, 300 Boston Post Rd, New Haven, CT 06511 USA
关键词
Approximate matching; Bloom filter; mrsh-v2; data loss prevention; network traffic analysis;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In recent years, Internet technologies changed enormously and allow faster Internet connections, higher data rates and mobile usage. Hence, it is possible to send huge amounts of data / files easily which is often used by insiders or attackers to steal intellectual property. As a consequence, data leakage prevention systems (DLPS) have been developed which analyze network traffic and alert in case of a data leak. Although the overall concepts of the detection techniques are known, the systems are mostly closed and commercial. Within this paper we present a new technique for network traffic analysis based on approximate matching (a.k.a fuzzy hashing) which is very common in digital forensics to correlate similar files. This paper demonstrates how to optimize and apply them on single network packets. Our contribution is a straightforward concept which does not need a comprehensive configuration: hash the file and store the digest in the database. Within our experiments we obtained false positive rates between 10(-4) and 10(-5) and an algorithm throughput of over 650 Mbit/s.
引用
收藏
页码:23 / 35
页数:13
相关论文
共 50 条
  • [1] Real Time Network File Similarity Detection Based on Approximate Matching
    Zhai, Aonan
    Xu, Fei
    Cao, Zigang
    Pan, Haiqing
    Li, Zhen
    Xiong, Gang
    2017 IEEE SECURITY AND PRIVACY WORKSHOPS (SPW 2017), 2017, : 223 - 228
  • [2] EVALUATION OF NETWORK TRAFFIC ANALYSIS USING APPROXIMATE MATCHING ALGORITHMS
    Goebel, Thomas
    Uhlig, Frieder
    Baier, Harald
    ADVANCES IN DIGITAL FORENSICS XVII, 2021, 612 : 89 - 108
  • [3] DESIGN FOR NETWORK FILE FORENSICS SYSTEM BASED ON APPROXIMATE MATCHING
    Xu, Fei
    Liu, Pinxin
    FORENSIC SCIENCE INTERNATIONAL, 2017, 277 : 120 - 120
  • [4] Peer-to-peer file sharing communication detection system using network traffic mining
    Togawa, Satoshi
    Kanenishi, Kazuhide
    Yano, Yoneo
    HUMAN INTERFACE AND THE MANAGEMENT OF INFORMATION: METHODS, TECHNIQUES AND TOOLS IN INFORMATION DESIGN, PT 1, PROCEEDINGS, 2007, 4557 : 769 - 778
  • [5] Parallel Scalable Approximate Matching Algorithm for Network Intrusion Detection Systems
    Hnaif, Adnan
    Jaber, Khalid
    Alia, Mohammad
    Daghbosheh, Mohammed
    INTERNATIONAL ARAB JOURNAL OF INFORMATION TECHNOLOGY, 2021, 18 (01) : 77 - 84
  • [6] Traffic Sign Detection Using Template Matching Technique
    Pandey, Pranjali
    Kulkarni, Ramesh
    2018 FOURTH INTERNATIONAL CONFERENCE ON COMPUTING COMMUNICATION CONTROL AND AUTOMATION (ICCUBEA), 2018,
  • [7] Approximate matching of network expressions with spacers
    Myers, EW
    JOURNAL OF COMPUTATIONAL BIOLOGY, 1996, 3 (01) : 33 - 51
  • [8] APPROXIMATE MATCHING OF NETWORK EXPRESSIONS WITH SPACERS
    MYERS, G
    LECTURE NOTES IN COMPUTER SCIENCE, 1992, 583 : 372 - 386
  • [9] Crypto-ransomware detection using machine learning models in file-sharing network scenarios with encrypted traffic
    Berrueta, Eduardo
    Morato, Daniel
    Magana, Eduardo
    Izal, Mikel
    EXPERT SYSTEMS WITH APPLICATIONS, 2022, 209
  • [10] Crypto-ransomware detection using machine learning models in file-sharing network scenarios with encrypted traffic
    Berrueta, Eduardo
    Morato, Daniel
    Magaña, Eduardo
    Izal, Mikel
    Expert Systems with Applications, 2022, 209