CookieMiner: Towards Real-Time Reconstruction of Web-Downloading from Online Network Traces

陈志鹏  张鹏  郑超  刘庆云 



Abstract: Network traces are one of the most exhaustive data sources for the forensic investigation of computer security incidents. Recent advances in capturing the network traces techniques have facilitated the forensic processing, including the reconstruction. Unfortunately, off-line web-downloading chain reconstruction could not meet the demands for real time processing. Furthermore, the packets in prior studies are mainly captured on the client or server side, which is difficult to monitor the network traffic in the real-time. Consequently, how to online reconstruct from the packets captured by the gateway is getting challenging. In this paper, based on the packets from the gateway, we propose a novel system, CookieMiner. CookieMiner first identifies the web-downloading resources, and then use the cookies to reconstruct the web-downloading chains reversely. All cookies would be firstly split into a series of tokens by semicolon and a threshold value will be set by the SET_K algorithm according to the number of tokens. Next, the HTTP packets whose tokens’ number is greater than the threshold will be sorted by timestamp and then inserted into the corresponding webdownloading chain. Finally, the most frequent URLs are extracted as entry points from all the chains with the same webdownloading resources. In addition, by a user study involving 6 pair-wise downloading applications, CookieMiner can reconstruct the webdownloading chains and find their entry points with high precision and low false positive rate. 

Keywords: real-time, network traffic, reconstruction




首页
团队介绍
发展历史
组织结构
MESA大事记
新闻中心
通知
组内动态
科研成果
专利
论文
项目
获奖
软著
人才培养
MESA毕业生
MESA在读生
MESA员工
招贤纳士
走进MESA
学长分享
招聘通知
招生宣传
知识库
文章
地址:北京市朝阳区华严北里甲22号楼五层 | 邮编:100029
邮箱:nelist@iie.ac.cn
京ICP备15019404号-1