Abstract
Enterprises have difficulty gaining insight into the steps preceding anomalous activity in end-user machines. En-Terprises may log events to later reconstruct anomalies to gain insight and determine their causes. Unfortunately, most logs are low-level and lack contextual information, making manual inspection arduous. Accordingly, enterprises may fail to promptly respond to anomalies, leading to outages or security breaches. To help these enterprises, we monitor and log each user's interactions with the machine's user interface (UI) and link them to the resulting network flows. We design, implement, and evaluate an SDN system, called Harbinger, for the Microsoft Windows OS that provides user activity context for flows. Enterprises can use the context we gather to complement traditional analysis. We explore how Harbinger can help differentiate normal and abnormal network traffic. While IP or DNS host name profiling can have error rates between 29%-38 % for URL-based traffic, UI-Aware sensors can reduce such errors to 0.2%. We further find that with the help of user action tracking, we can detect errant network traffic 99.1% of the time in our tests. HARBINGERhas good performance, introducing less than 6 milliseconds of delay in 95% of new network flows.
Original language | English |
---|---|
Title of host publication | 2021 8th International Conference on Software Defined Systems, SDS 2021 |
Editors | Pradeeban Kathiravelu, Jaime Lloret Mauri, Yaser Jararweh, Elhadj Benkhelifa, Sandra Sendra |
Publisher | Institute of Electrical and Electronics Engineers Inc. |
ISBN (Electronic) | 9781665458207 |
DOIs | |
State | Published - 2021 |
Event | 8th International Conference on Software Defined Systems, SDS 2021 - Virtual, Gandia, Spain Duration: Dec 6 2021 → Dec 9 2021 |
Publication series
Name | 2021 8th International Conference on Software Defined Systems, SDS 2021 |
---|
Conference
Conference | 8th International Conference on Software Defined Systems, SDS 2021 |
---|---|
Country/Territory | Spain |
City | Virtual, Gandia |
Period | 12/6/21 → 12/9/21 |
Funding
ACKNOWLEDGMENTS This material is based upon work supported by the National Science Foundation under Grant No. 1422180. Shue holds stock in ContexSure Networks, Inc., an arrangement that has been reviewed and approved by WPI.