通过流量建模识别加密网络中用户身份与行为,准确率达93.3%。
An Identity and Interaction Based Network Forensic Analysis
- 基于流量模式建模,不依赖IP识别真实用户
- 在27名用户上实现93.3%的识别准确率,41%达100%准确
- 适合调查加密应用中的用户行为,如Skype、Wikipedia
在电子犯罪日益增多的背景下,网络取证对数字调查至关重要。然而现有网络取证工具(NFATs)在提供可用数据方面仍远不及文件系统取证工具(FS FATs)。传统分析聚焦于IP地址,但其无法等同于用户身份,这正是调查人员关注的重点。本文提出一种新型NFAT方法,可在加密流量下识别用户并理解其使用网络应用的行为。实验基于5000万包的自建数据集,分三阶段逐步提升性能。针对27名用户的研究显示,平均真阳性识别率为93.3%,其中41%用户达到100%识别率。Skype、Wikipedia和Hotmail服务表现尤为突出。研究开发并评估了通过建模网络流量实现有效分析的方法,并设计了可视化交互界面,便于调查人员查询用户互动关系。
原文摘要 · Abstract (English)
In todays landscape of increasing electronic crime, network forensics plays a pivotal role in digital investigations. It aids in understanding which systems to analyse and as a supplement to support evidence found through more traditional computer based investigations. However, the nature and functionality of the existing Network Forensic Analysis Tools (NFATs) fall short compared to File System Forensic Analysis Tools (FS FATs) in providing usable data. The analysis tends to focus upon IP addresses, which are not synonymous with user identities, a point of significant interest to investigators. This paper presents several experiments designed to create a novel NFAT approach that can identify users and understand how they are using network based applications whilst the traffic remains encrypted. The experiments build upon the prior art and investigate how effective this approach is in classifying users and their actions. Utilising an in-house dataset composed of 50 million packers, the experiments are formed of three incremental developments that assist in improving performance. Building upon the successful experiments, a proposed NFAT interface is presented to illustrate the ease at which investigators would be able to ask relevant questions of user interactions. The experiments profiled across 27 users, has yielded an average 93.3% True Positive Identification Rate (TPIR), with 41% of users experiencing 100% TPIR. Skype, Wikipedia and Hotmail services achieved a notably high level of recognition performance. The study has developed and evaluated an approach to analyse encrypted network traffic more effectively through the modelling of network traffic and to subsequently visualise these interactions through a novel network forensic analysis tool.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。