Inferring the presence of reverse proxies through timing analysis

Download
Author
Alexander, Daniel R.
Date
2015-06Advisor
Xie, Geoffrey
Beverly, Robert
Metadata
Show full item recordAbstract
This thesis presents a method for inferring the presence of a reverse proxy server using packet timing analysis from the vantage point of a client system. This method can determine whether Internet users are receiving web content from the actual source or from some potentially spoofed proxy device; leading to better risk assessment and understanding of the cyber terrain. By using only the measurement and comparison of three-way handshake and content request/delivery packet round trip times, we identify an accurate classifier that detects the presence of a reverse proxy server with over 98% accuracy. This is an improvement over other inference methods because all measurements can be done from an external client machine. A secondary yet significant contribution is the robust data set that was produced as a result of this research. We have collected a set of over 6 million data points from a known set of 30 globally dispersed machines, which was instrumental in our research efforts and will be used for further studies and exploration.
Rights
This publication is a work of the U.S. Government as defined in Title 17, United States Code, Section 101. Copyright protection is not available for this work in the United States.Related items
Showing items related by title, author, creator and subject.
-
Narrowband filtering effects on frequency-hopped signals
Waters, Kevin A. (Monterey, Calif. Naval Postgraduate School, 2002-12);A low complexity solution to remove follower, narrowband tone jamming signals which are randomly dispersed within the bandwidth of a hop without causing non-linear phase distortions in a frequency-hopping (FH) system is ... -
Performance of coherent and noncoherent RAKE receivers with convolutional coding ricean fading and pulse-noise interference
Kowalske, Kyle E. (Monterey, California. Naval Postgraduate School, 2004-06);The performance of coherent and noncoherent RAKE receivers over a fading channel in the presence of pulse-noise interference and additive white Gaussian noise is analyzed. Coherent RAKE receivers require a pilot tone for ... -
ARMENIA-AZERBAIJAN WAR AND IMPLICATIONS FOR RUSSIA
Kochashvili, Irakli (Monterey, CA; Naval Postgraduate School, 2022-03);In September 2020, tensions in Nagorno-Karabakh escalated into a full-scale war that ended with a tripartite ceasefire agreement on November 9, 2020. The consequences of the war have significantly changed the status quo ...