NSA-CSEC IP Profiling Analytics-Mission Impacts.pdf

(2044 KB) Pobierz
TOP SECRET
IPProfilingAnalytics
&MissionImpacts
TradecraftDeveloper
CSEC–NetworkAnalysisCentre
May10,2012
1251391800.014.png 1251391800.015.png
TOP SECRET
ExampleIPProfileProblem
Target appears on IP address, wish to understand
network context more fully
Example Quova look-up & response for
Lat. 60.00 Long: -95.00 (in frozen tundra W. of Hudson Bay)
City: unknown
Country: Canada,
Operator: Bell Canada, Sympatico
Issues with IP look-up data:
is it actually revealing, or is it opaque
is the data even current, or is it out-of-date
was the data ever accurate in the first place
2
1251391800.016.png 1251391800.017.png
TOP SECRET
Objectives
Develop new analytics to provide richer contextual
data about a network address
Apply analytics against Tipping & Cueing objectives
Build upon artefact of techniques to develop new
needle-in-a-haystack analytic – contact chaining
across air-gaps
3
1251391800.001.png 1251391800.002.png
TOP SECRET
AnalyticConcept–StartwithTravelNode
Beginwith single seedWi-FiIPaddressofintl.airport
AssemblesetofuserIDsseenonnetworkaddress
overtwoweeks
4
1251391800.003.png 1251391800.004.png 1251391800.005.png
TOP SECRET
ProfilingTravelNodes–NextStep
FollowIDsbackwardandforwardinrecenttime
EarlierIPclustersof:
- localhotels
- domesticairports
- localtransportationhubs
- localinternetcafes
LaterIPclustersof:
- otherintl.airports
- domesticairports
- majorintl.hotels
- etc.
-etc.
5
1251391800.006.png 1251391800.007.png 1251391800.008.png 1251391800.009.png 1251391800.010.png 1251391800.011.png 1251391800.012.png 1251391800.013.png
Zgłoś jeśli naruszono regulamin