Increasing the darkness of darknet traffic

Yumehisa Haga, Akira Saso, Tatsuya Mori, Shigeki Goto

研究成果: Conference contribution

抄録

A Darknet is a passive sensor system that monitors traffic routed to unused IP address space. Darknets have been widely used as tools to detect malicious activities such as propagating worms, thanks to the useful feature that most packets observed by a darknet can be assumed to have originated from non-legitimate hosts. Recent commoditization of Internet-scale survey traffic originating from legitimate hosts could overwhelm the traffic that was originally supposed to be monitored with a darknet. Based on this observation, we posed the following research question: »Can the Internet-scale survey traffic become noise when we analyze darknet traffic?» To answer this question, we propose a novel framework, ID2, to increase the darkness of darknet traffic, i.e., ID2 discriminates between Internet-scale survey traffic originating from legitimate hosts and other traffic potentially associated with malicious activities. It leverages two inrinsic characteristics of Internet-scale survey traffic: a network- level property and some form of footprint explicitly indicated by surveyors. When we analyzed darknet traffic using ID2, we saw that Internet-scale traffic can be noise. We also demonstrated that the discrimination of survey traffic exposes hidden traffic anomalies, which are invisible without using our technique.

本文言語English
ホスト出版物のタイトル2015 IEEE Global Communications Conference, GLOBECOM 2015
出版社Institute of Electrical and Electronics Engineers Inc.
ISBN(電子版)9781479959525
DOI
出版ステータスPublished - 2015
イベント58th IEEE Global Communications Conference, GLOBECOM 2015 - San Diego, United States
継続期間: 2015 12月 62015 12月 10

出版物シリーズ

名前2015 IEEE Global Communications Conference, GLOBECOM 2015

Other

Other58th IEEE Global Communications Conference, GLOBECOM 2015
国/地域United States
CitySan Diego
Period15/12/615/12/10

ASJC Scopus subject areas

  • コンピュータ ネットワークおよび通信
  • 電子工学および電気工学
  • 通信

フィンガープリント

「Increasing the darkness of darknet traffic」の研究トピックを掘り下げます。これらがまとまってユニークなフィンガープリントを構成します。

引用スタイル