Uncovering identities: a study into VPN tunnel fingerprinting

dc.contributor.authorIzadinia, Vafa Dario
dc.contributor.authorKourie, Derrick G.
dc.contributor.authorEloff, Jan H.P.
dc.date.accessioned2007-02-15T15:06:54Z
dc.date.available2007-02-15T15:06:54Z
dc.date.issued2006
dc.description.abstractOperating System fingerprinting is a reconnaissance method which can be used by attackers or forensic investigators. It identifies a system's identity by observing its responses to targeted probes, or by listening on a network and passively observing its network ‘etiquette’. The increased deployment of encrypted tunnels and Virtual Private Networks (VPNs) calls for the formulation of new fingerprinting techniques, and poses the question: “How much information can be gleaned from encrypted tunnels?” This paper investigates IPSec VPN tunnel-establishment and tear-down on three IPSec implementations: Microsoft Windows 2003, Sun Solaris 9 x86, and racoon on Linux 2.6 kernel. By analysing each platform's Internet Key Exchange (IKE) messages, which negotiate the IPSec tunnel, we identify a number of discriminants, and show that each of these platforms can be uniquely identified by them. We also show that the nature of some encrypted traffic can be determined, thus giving the observer an idea of the type of communication that is taking place between the IPSec endpoints.en
dc.description.departmentComputer Science
dc.format.extent179758 bytes
dc.format.mimetypeapplication/pdf
dc.identifier.citationIzadinia, VD, Kourie, DG & Eloff, JHP 2006, ‘Uncovering identities: a study into VPN tunnel fingerprinting’, Computers & Security, vol.25, issue 2, pp. 97-105 [http://www.sciencedirect.com/science/journal/01674048]en
dc.identifier.isbn10.1016/j.cose.2005.12.008
dc.identifier.issn0167-4048
dc.identifier.urihttp://hdl.handle.net/2263/1793
dc.language.isoenen
dc.publisherElsevieren
dc.rightsElsevieren
dc.subjectIPSecen
dc.subjectInternet Key Exchange (IKE)en
dc.subjectFingerprintingen
dc.subjectTraffic analysisen
dc.subjectVirtual Private Network (VPN)en
dc.titleUncovering identities: a study into VPN tunnel fingerprintingen
dc.typeArticleen

Files

Original bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
Izadinia_Uncovering(2006).pdf
Size:
175.54 KB
Format:
Adobe Portable Document Format

License bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
license.txt
Size:
2.39 KB
Format:
Item-specific license agreed upon to submission
Description: