Detecting and Interpreting Changes in Scanning Behavior in Large Network Telescopes

Detecting and Interpreting Changes in Scanning Behavior in Large Network Telescopes
复制标题

DOI:
10.1109/tifs.2022.3211644
复制
发表时间:
2022
影响因子:
6.8
通讯作者:
Michalis Kallitsis;Rupesh Prajapati;Vasant G Honavar;Dinghao Wu
Michalis Kallitsis;Rupesh Prajapati;Vasant G Honavar;Dinghao Wu
中科院分区:
计算机科学1区
文献类型:
--
作者:
Michalis Kallitsis;Rupesh Prajapati;Vasant G Honavar;Dinghao Wu

文献摘要

被引文献

相似文献

网络望远镜或“暗网”接收未经请求的互联网范围内的流量,从而提供了一个独特的窗口,观察与恶意软件传播、拒绝服务攻击、网络侦察、错误配置和网络中断有关的宏观互联网活动。对结果数据的分析可以为安全分析师提供可操作的见解,可用于预防或减轻网络威胁。然而,大型网络望远镜每天都在观察数百万次恶意扫描活动,这使得将捕获的信息转化为有意义的威胁情报具有挑战性。为了解决这一挑战,我们提出了一个新的框架来描述在网络望远镜中观测到的扫描行为的结构和时间演变。提议的框架包括四个部分。它(i)提取由网络望远镜数据提取的特征组成的扫描轮廓的丰富、高维表示;(ii)使用适合聚类的深度表示学习,以无监督的方式学习这些扫描行为的信息保存简洁表示;(iii)在每日暗网数据的潜在表示空间中对扫描仪配置文件进行聚类;(iv)使用最佳质量传输技术检测扫描行为的时间变化。我们使用合成数据和真实的暗网数据对所提出的系统进行了稳健评估。我们展示了其检测现实世界,高影响网络安全事件的能力,例如2016年底Mirai僵尸网络的发作,以及2022年初几个有趣的集群形成(例如,重型扫描仪,进化的Mirai变体,暗网“反向散射”活动等)。与最先进的方法的比较表明,所提出的特征与深度表示学习方案的集成导致了暗网扫描仪更好的分类性能。
Network telescopes or “Darknets” received unsolicited Internet-wide traffic, thus providing a unique window into macroscopic Internet activities associated with malware propagation, denial of service attacks, network reconnaissance, misconfigurations and network outages. Analysis of the resulting data can provide actionable insights to security analysts that can be used to prevent or mitigate cyber-threats. Large network telescopes, however, observe millions of nefarious scanning activities on a daily basis which makes the transformation of the captured information into meaningful threat intelligence challenging. To address this challenge, we present a novel framework for characterizing the structure and temporal evolution of scanning behaviors observed in network telescopes. The proposed framework includes four components. It (i) extracts a rich, high-dimensional representation of scanning profiles composed of features distilled from network telescope data; (ii) learns, in an unsupervised fashion, information-preserving succinct representations of these scanning behaviors using deep representation learning that is amenable to clustering; (iii) performs clustering of the scanner profiles in the resulting latent representation space on daily Darknet data, and (iv) detects temporal changes in scanning behavior using techniques from optimal mass transport. We robustly evaluate the proposed system using both synthetic data and real-world Darknet data. We demonstrate its ability to detect real-world, high-impact cybersecurity incidents such as the onset of the Mirai botnet in late 2016 and several interesting cluster formations in early 2022 (e.g., heavy scanners, evolved Mirai variants, Darknet “backscatter” activities, etc.). Comparisons with state-of-the-art methods showcase that the integration of the proposed features with the deep representation learning scheme leads to better classification performance of Darknet scanners.