Blacklist Ecosystem Analysis: Spanning Jan 2012 to Jun 2014

Blacklist Ecosystem Analysis: Spanning Jan 2012 to Jun 2014
复制标题

黑名单生态系统分析:2012 年 1 月至 2014 年 6 月

DOI:
--
复制
发表时间:
2015
期刊:
WISCS@CCS
影响因子:
--
通讯作者:
Jonathan M. Spring
Jonathan M. Spring
中科院分区:
--
文献类型:
--
作者:
Leigh Metcalf;Jonathan M. Spring

文献摘要

被引文献

相似文献

动机:我们比较了86个互联网黑名单的内容,以提供一个整个生态系统的封锁网络接触点和黑名单的视图。我们的目标是形式化和评估实践者对对抗有弹性的对手资源玩“打地鼠”的疲劳的隐性知识。方法:将列表与相同数据类型(域名或IP地址)的列表进行比较。研究的不同阶段使用不同的比较。比较包括一个指标在多少个列表中是唯一的;列表大小;扩展列表表征与交集;所有列表的成对相交;接下来,我们定义一个统计测试来确定一个列表是否在另一个列表之后不久添加元素。结果:在多种方法综合的基础上,基于域名的指标在同一列表中唯一的概率为96.16% ~ 97.37%。基于ip地址的指标有82.46% ~ 95.24%的情况下是唯一的。讨论:黑名单之间几乎没有重叠。尽管有例外,但即使将每个列表扩展到相关指标的更大区域,列表之间的交集仍然很低。如果有交集,很少有列表总是在其他列表之前提供内容。这些结果表明,每个黑名单都描述了一种不同类型的恶意活动,即使合并所有列表,也无法获得全球的基本真相。实际的见解包括(1)建议网络防御者获取和评估尽可能多的列表,(2)由于列表动态,“打地鼠”是不可避免的,除非战略改变,(3)学者将他们的结果与一个或几个黑名单进行比较,以测试准确性,建议重新考虑这种验证技术。
Motivation: We compare the contents of 86 Internet blacklists to provide a view of the whole ecosystem of blocking network touch points and blacklists. We aim to formalize and evaluate practitioner tacit knowledge of the fatigue of playing "whack-a-mole" against resilient adversary resources. Method: Lists are compared to lists of the same data type (domain name or IP address). Different phases of the study use different comparisons. Comparisons include how many lists an indicator is unique to; list sizes; expanded list characterization and intersection; pairwise intersections of all lists; and following, a statistical test we define to determine if one list adds elements shortly after another. Results: Based on a synthesis of multiple methods, domain-name-based indicators are unique to one list 96.16% to 97.37% of the time. IP-address-based indicators are unique to one list 82.46% to 95.24% of the time. Discussion: There is little overlap between blacklists. Though there are exceptions, the intersection between lists remains low even after expanding each list to a larger neighborhood of related indicators. Few lists consistently provide content before other lists if there is intersection. These results suggest that each blacklist describes a distinct sort of malicious activity and that even merging all lists there is no global ground truth to acquire. Practical insights include (1) network defenders are advised to obtain and evaluate as many lists as practical, (2) "whack-a-mole" is inevitable due to list dynamics, barring a strategic change, an (3) academics comparing their results to one or a few blacklists to test accuracy are advised to reconsider this validation technique.