D 2018

Passive OS Fingerprinting Prototype Demonstration

LAŠTOVIČKA, Martin and Daniel FILAKOVSKÝ

Basic information

Original name

Passive OS Fingerprinting Prototype Demonstration

Authors

LAŠTOVIČKA, Martin and Daniel FILAKOVSKÝ

Edition

Taipei, Taiwan, NOMS 2018 - 2018 IEEE/IFIP Network Operations and Management Symposium, p. nestránkováno, 2 pp. 2018

Publisher

IEEE Xplore Digital Library

Other information

Language

English

Type of outcome

Proceedings paper

Confidentiality degree

is not subject to a state or trade secret

Publication form

electronic version available online

References:

Marked to be transferred to RIV

Yes

RIV identification code

RIV/00216224:14610/18:00106884

Organization

Ústav výpočetní techniky – Repository – Repository

ISBN

978-1-5386-3416-5

EID Scopus

Keywords in English

OS fingerprinting;passive monitoring;Network model

Links

VI20172020070, research and development project.
Changed: 17/5/2022 04:14, RNDr. Daniel Jakubík

Abstract

In the original language

Operating system identification of communicating devices plays an important part in network protection. However, current networks are large and change often which implies the need for a system that will be able to continuously monitor the network and handle changes in identified operating systems. In this paper, we propose an architecture of an OS fingerprinting system based on passive network monitoring and a graph-based data model to store and present information about operating systems in the network. We implemented the proposed architecture and tested it on the backbone network of Masaryk University. Our results suggest that it is suitable for monitoring a large network with tens of thousands of actively communicating devices.

Files attached