27.06.2013 Views

6th European Conference - Academic Conferences

6th European Conference - Academic Conferences

6th European Conference - Academic Conferences

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Stephen Groat et al.<br />

probability follows a hypergeometric distribution. In the case of locating specific hosts on a subnet, the<br />

probability can be written as:<br />

where N represents the total possible addresses in the subnet, h represents the target host(s), and r<br />

represents the number of guesses an attacker takes in an attempt to find the target address(es).<br />

The best case for the target host is if its address changes at the same rate that an attacker scans a<br />

single address. To provide the fairest assessment, we assume a scenario where the attacker is aware<br />

of the target host changing his/her address. As a result, the attacker randomizes his/her address<br />

guesses, allowing for repetition of addresses. This is in contrarst to the normal approach where an<br />

attacker exhaustively scans a subnet without repetition. The probability of detecting the target host<br />

using an exhaustive search is slightly lower due to the possibility of a host address changing to a<br />

previously guessed address. In the attacker-aware scenario, the probability of detecting the target<br />

host remains the same with each subsequent guess and follows a cumulative binomial distribution as<br />

shown in Equation 2<br />

where N again represents the total possible addresses in the subnet and r represents the attempt<br />

during which detections occurs. Figure 1 depicts the difference between the probabilities of a static<br />

address versus a changing address that follows a binomial distribution. A subnet of size 256 hosts is<br />

used as an example for this figure.<br />

Figure 1: The probability an attacker has of detecting a target address within r attempts, the solid line<br />

represents the probability given a static address while the dotted line represents the<br />

probability if the address is changed at the same rate it is scanned<br />

87<br />

(1)<br />

(2)

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!