Assessing Internet-wide Cyber Situational Awareness of Critical Sectors

Assessing Internet-wide Cyber Situational Awareness of Critical Sectors
复制标题

评估关键部门的全互联网网络态势感知

DOI:
10.1145/3230833.3230837
复制
发表时间:
2018
期刊:
Reliability and Security
影响因子:
--
通讯作者:
Čeleda, Pavel
Čeleda, Pavel
中科院分区:
--
文献类型:
--
作者:
Husák, Martin;Neshenko, Nataliia;Pour, Morteza Safaei;Bou-Harb, Elias;Čeleda, Pavel

文献摘要

参考文献

被引文献

相似文献

在这篇短文中,我们迈出了经验评估互联网范围内恶意活动的第一步,这些恶意活动来自互联网规模的商业部门(即金融、卫生、教育等)和关键基础设施(即公用事业、制造业、政府等)。在创新和协作的大规模努力的推动下,我们与众多互联网实体进行了讨论,以获取与上述部门和关键基础设施相关的分配IP块相关的罕见和私人信息。为此,我们利用这些信息将互联网规模的恶意归咎于这些部门和领域,试图提供对全球网络态势的深入分析。我们利用近16.8 TB的暗网数据来推断探测活动(通常由恶意/受感染的主机生成)和DDoS反向散射,从中提取受害者的IP地址。通过执行为期一周的测量,我们观察到关键部门托管的超过11,000台探测机器和300个DDoS攻击受害者的数量惊人。我们还对包括金融在内的各种商业部门的恶意行为产生了罕见的见解,这些部门通常不会报告其托管和针对性的非法活动,以维护声誉。虽然由于明显的敏感性原因,我们严格保密所获得的结果,但我们假设这些生成的网络威胁情报可以与部门/关键基础设施运营商、骨干网络和互联网服务提供商共享,以促进整体威胁补救目标。
In this short paper, we take a first step towards empirically assessing Internet-wide malicious activities generated from and targeted towards Internet-scale business sectors (i.e., financial, health, education, etc.) and critical infrastructure (i.e., utilities, manufacturing, government, etc.). Facilitated by an innovative and a collaborative large-scale effort, we have conducted discussions with numerous Internet entities to obtain rare and private information related to allocated IP blocks pertaining to the aforementioned sectors and critical infrastructure. To this end, we employ such information to attribute Internet-scale maliciousness to such sectors and realms, in an attempt to provide an in-depth analysis of the global cyber situational posture. We draw upon close to 16.8 TB of darknet data to infer probing activities (typically generated by malicious/infected hosts) and DDoS backscatter, from which we distill IP addresses of victims. By executing week-long measurements, we observed an alarming number of more than 11,000 probing machines and 300 DDoS attack victims hosted by critical sectors. We also generate rare insights related to the maliciousness of various business sectors, including financial, which typically do not report their hosted and targeted illicit activities for reputation-preservation purposes. While we treat the obtained results with strict confidence due to obvious sensitivity reasons, we postulate that such generated cyber threat intelligence could be shared with sector/critical infrastructure operators, backbone networks and Internet service providers to contribute to the overall threat remediation objective.
DOI: 10.1007/978-3-030-46908-5_2
发表时间: 2020
期刊: Advanced Sciences and Technologies for Security Applications
影响因子: --
作者:
S. Rass;S. Schauer;Sandra König;Quanyan Zhu
通讯作者: S. Rass;S. Schauer;Sandra König;Quanyan Zhu
DOI: --
发表时间: 2014
期刊: 39th Annual IEEE Conference on Local Computer Networks Workshops
影响因子: --
作者:
Eray Balkanli;Nur Zincir
通讯作者: Nur Zincir
通过互联网反向散射量化拒绝服务攻击的范围
DOI: --
发表时间: 2017
期刊: ARES
影响因子: --
作者:
Norbert Blenn;Vincent Ghiëtte;C. Doerr
通讯作者: C. Doerr
暗网作为网络情报的来源:调查、分类和表征
DOI: --
发表时间: 2016
影响因子: 35.6
作者:
Claude Fachkha;M. Debbabi
通讯作者: M. Debbabi
DOI: --
发表时间: 2015
期刊: IEEE Conference on Communications and Network Security
影响因子: --
作者:
Emmanouil Vasilomanolakis;Shreyas Srinivasa;M. Mühlhäuser
通讯作者: M. Mühlhäuser