Institute for Internet-Security
if(is)

Links  | Kontakt  | Sitemap  | Impressum  |  if(is) auf Twitter if(is) Facebook if(is)
Internet Analysis System

Perception of a TCP-SYN-Scan

As an example for the analysis of the probe data, we display the TCP Handshake and the TCP Teardown here:

Grafik: TCP Handshake and Teardown

This pictured is based on Tcp-handshake.png and Tcp-teardown.png from the free encyclopaedia Wikipedia and is under GNU licence for free documentations. The author of the picture can be found under the declared web sites.

Within a TCP Handshake a SYN/ACK packet follows a SYN packet. So there should be a ratio of 1:1 between the distributions of SYN packets to SYN/ACK packets. Each connection is closed through TCP Teardown. The Teardown is initiated through the sending of a FIN/ACK packet and is confirmed through a FIN/ACK packet from the receiver.  The ACK packets that are used for termination of handshake and teardown can’t be distinguished by IAS from regular ACK packets that confirm data packets and therefore are not taken into account.

The distribution of  packets participating on a TCP Handshake and TCP Teardown, averages in best case 25% SYN, 25% SYN/ACK und 50% FIN/ACK.

Grafik: Summenvergleich der Normalverteilung

SYN        28% 2.958.989 (yellow)
SYN/ACK:     24% 2.499.114 (cyan)
FIN/ACK:     39% 3.517.614
FIN/ACK/PSH:  4% 371.406
FIN:          0% 7
RST:          3% 312.021
RST/ACK:      3% 306.008

The data shows that not each try to establish a connection is successful and that not each connection can be established.
The RST packets result from faulty connections and from unsuccessful connection attempts on closed ports.

On the basis of this information and within small time intervals an anomaly can be detected.
The following time diagram shows the distribution of TCP connection control packets over one day: 

Grafik: Syn Scan

The shift in distribution can be clearly recognized. Taking into account the percent distribution of packets at this time shows the difference to a normal distribution.

Grafik: Syn Scan Pie

SYN:        44%   8.005 (yellow)
SYN/ACK:    16%   2.863 (cyan)
FIN/ACK:    26%   4.601
FIN/ACK/PSH: 3%     551
FIN:         0%       0
RST:         2%     374
RST/ACK:     9%   1.645

This demonstrates that IAS is able to display the actual state of the connection as well as jump changes.

Browser statistic

A very interesting statistic is the browser usage statistic:
Conventional web browser statistics are levied through the analysis of log files. The web server saves the “http User Agent Header” value in his log files.
Evaluation software like “awstats” evaluates log files and displays besides other information the usage of web browsers. But these statistics only take into account the usage of web browsers relating to a specific web server.

IAS also evaluates the „User Agent“ Header, but the evaluation is done on the line. So this is a totally different kind of statistic. When evaluating log files, the user group consists of the web server’s users. The IAS evaluation is different its user group consists of the users sharing the line to be analyzed.

The following graphics show the distribution in browser usage (inbound and outbound accumulated) for the IT faculty between the mid of august 2005 and the beginning of 2006.
We can see that IE 6 and Mozilla Firefox dominate the traffic.
A separate analysis for in and outbound traffic is in preparation.

Grafik: Browser long-time timechart weekly
Grafik: Browser long-time pie

Taking a look at the graphs, the faculty’s complete WWW traffic can be estimated. The noticeable break-ins in traffic result from periods where regular operation of the faculty was limited.

Regular operation and especially the use of the student pools start slowly from here. The three noticeable break-ins result from the two bridge days (German Unification Day and All Hallows), as well as from the three Christmas days.

Very interesting in this context: wget doesn’t seem to be much impressed by public holidays.  This is due to the fact that wget is often used in scripts to download files in defined time intervals. For example virus scanner updates or the newest files for a mirror servers.

Grafik: Browser long-time timechart weekly dates

Observation of the CME-151 Worm(Sober)

Indicators for the worm CME-151 CME-151, known as a sober worm variant, can be found in the IAS data.
(See also: MS05-039)

Grafik: Wurm CME-151

The worm first appeared on October the 6th 2005. It distributes itself through its own STMP engine and spreads itself as a windows pe.exe file (UPX)
The attachment can be identified through the content type when it’s multipart.
The clearly noticeable jump of incoming E-Mails with attachments is a reliable indicator for the break out of the worm.



Link zum moeglichen Abschlussarbeiten des if(is)
Marktplatz IT-Sicherheit, Lösungen, Anbieter, Dienstleistungen, IT-Jobs
Anbieter finden!
Jobs finden!

Logo zum neuen Studiengang: Master Internet-SicherheitEinstieg auch zum
Sommersemster!


Logo zum Professor des Jahres 2011

Logo: Buch Sicher im Internet

Logo: DIX - Deutscher Internet-Index

Logo: Frühwarn- und Intrusion Detection-System auf der Basis von kombinierten Methoden der KI

Logo: Live Hacking / Awareness Performance

Logo: Turaya