Back to results

University of Wolverhampton

A novel flow-based statistical pattern recognition architecture to detect and classify pivot attacks

Abstract

dc:description.abstract

Pivot attack or pivoting is a well-known technique used by threat actors to cover their tracks and overcome connectivity restrictions imposed by the network defences or topology. Therefore, detecting ongoing pivot attacks while the opponent has not yet achieved their goals is essential for a solid defence strategy. However, recognising and classifying this technique in large corporate networks is a complex task. The literature presents limited studies regarding pivot attacks, and mitigation strategies have severe constraints to date. For example, related work still focuses on specific protocol restrictions techniques scoped at internal network assets only. This approach is inefficient since opponents commonly create pivot tunnels across the internet. This thesis introduces and evaluates APIVADS, a novel flow-based detection scheme to identify compromised assets supporting pivot attacks. Moreover, APIVADS outperforms previous approaches regarding features and capacities. To the best of our knowledge, this is the first protocol and cryptographic primitives agnostic, privacy-preserving approach capable of detecting pivot attacks over the internet. For example, Its efficient data reduction technique can achieve near real-time detection accuracy of 99.37% by distinguishing ongoing pivot attacks from regular enterprise traffic such as TLS, HTTPS, DNS and P2P over the internet. Additionally, this thesis proposes APCA, an automatic pivot attack classifier algorithm based on perceived indicators of attack (IoA) generated by APIVADS, to determine the level of connectivity achieved by the adversary. APCA can distinguish between different types of pivoting and contribute to the threat intelligence capabilities regarding the adversary modus operandi. The architecture composed by APIVADS and APCA considers a hybrid approach between decentralised pivoting host-based detection and a centralised approach to aggregate results and achieve scalability. Empirical results from our experiments show that even when the adversary uses evasive pivoting techniques, the proposed architecture is efficient and feasible regarding classification and detection, achieving high accuracy of 98.54% and low false positives.

Degree

thesis:*
Name dc:type.qualificationname
PhD
Level dc:type.qualificationlevel
Doctoral
Grantor dc:publisher.institution
University of Wolverhampton
Year dc:date.issued
2022

Author and committee

dc:creator, dc:contributor.*
Author dc:creator
  • Marques, Rafael Salema
Advisor dc:contributor.advisor
  • Al-Khateeb, Haider

Subjects

dc:subject × 7

Rights

dc:rights
Statement dc:rights
  • Attribution-NonCommercial-NoDerivatives 4.0 International

Chain of custody

source
Harvested from
University of Wolverhampton
Base URL
wlv.openrepository.com/server/oai/request
Last updated
2026-07-24
Source record
OAI-PMH GetRecord
citation

Marques, Rafael Salema. A novel flow-based statistical pattern recognition architecture to detect and classify pivot attacks. Doctoral thesis, University of Wolverhampton, 2022.