BLAG: Improving the Accuracy of Blacklists

BLAG: Improving the Accuracy of Blacklists
复制标题

DOI:
10.14722/ndss.2020.24232
复制
发表时间:
2020
期刊:
Proceedings 2020 Network and Distributed System Security Symposium
影响因子:
--
通讯作者:
Sivaramakrishnan Ramanathan;J. Mirkovic;Minlan Yu
Sivaramakrishnan Ramanathan;J. Mirkovic;Minlan Yu
中科院分区:
其他
文献类型:
--
作者:
Sivaramakrishnan Ramanathan;J. Mirkovic;Minlan Yu

文献摘要

相似文献

-IP地址黑名单是有关重复攻击者的有用信息来源。这样的信息可以被用来区分哪个Traffic转移以进行更深入的检查(例如,重复犯罪者Traffic),或者哪个Traffic服务于first(例如,来自未被列入黑名单的源的Traffic)。但黑名单也存在过度专业化的问题--每个名单都针对一个特定的目的--它们可能会因为错误的fi引用或过时的信息而不准确。我们提出了BLAG,这是一个评估和聚合多个黑名单提要的系统,生成一个更有用、更准确和更及时的主黑名单,专为Speific客户网络定制。BLAG使用客户网络入站Traffic的合法来源样本来评估地址空间区域内每个黑名单的准确性。然后,它利用推荐系统选择最准确的信息,将其汇总到其主黑名单中。最后,BLAG identifi主黑名单的ES部分可以扩展到更大的地址区域(例如/24fiXES之前),以发现更多的恶意地址,并将附带损害降至最低。我们对不同攻击类型的157个黑名单和三个真实数据集的评估表明,BLAG实现了高达99%的fi城市精确度,与竞争方法相比,召回率提高了114倍,检测攻击的时间缩短了13.7天,这使得它成为一种很有前途的黑名单生成方法。
—IP address blacklists are a useful source of information about repeat attackers. Such information can be used to prioritize which traffic to divert for deeper inspection (e.g., repeat offender traffic), or which traffic to serve first (e.g., traffic from sources that are not blacklisted). But blacklists also suffer from overspecialization – each list is geared towards a specific purpose – and they may be inaccurate due to misclassification or stale information. We propose BLAG, a system that evaluates and aggregates multiple blacklists feeds, producing a more useful, accurate and timely master blacklist , tailored to the specific customer network. BLAG uses a sample of the legitimate sources of the customer network’s inbound traffic to evaluate the accuracy of each blacklist over regions of address space. It then leverages recommendation systems to select the most accurate information to aggregate into its master blacklist. Finally, BLAG identifies portions of the master blacklist that can be expanded into larger address regions (e.g. /24 prefixes) to uncover more malicious addresses with minimum collateral damage. Our evaluation of 157 blacklists of various attack types and three ground-truth datasets shows that BLAG achieves high specificity up to 99%, improves recall by up to 114 times compared to competing approaches, and detects attacks up to 13.7 days faster, which makes it a promising approach for blacklist generation.