Assessing Internet-wide Cyber Situational Awareness of Critical Sectors
Assessing Internet-wide Cyber Situational Awareness of Critical Sectors
复制标题
评估关键部门的全互联网网络态势感知
DOI:
10.1145/3230833.3230837
复制
发表时间:
2018
期刊:
影响因子:
--
通讯作者:
Čeleda, Pavel
中科院分区:
文献类型:
--
作者:
Husák, Martin;Neshenko, Nataliia;Pour, Morteza Safaei;Bou-Harb, Elias;Čeleda, Pavel
In this short paper, we take a first step towards empirically assessing Internet-wide malicious activities generated from and targeted towards Internet-scale business sectors (i.e., financial, health, education, etc.) and critical infrastructure (i.e., utilities, manufacturing, government, etc.). Facilitated by an innovative and a collaborative large-scale effort, we have conducted discussions with numerous Internet entities to obtain rare and private information related to allocated IP blocks pertaining to the aforementioned sectors and critical infrastructure. To this end, we employ such information to attribute Internet-scale maliciousness to such sectors and realms, in an attempt to provide an in-depth analysis of the global cyber situational posture. We draw upon close to 16.8 TB of darknet data to infer probing activities (typically generated by malicious/infected hosts) and DDoS backscatter, from which we distill IP addresses of victims. By executing week-long measurements, we observed an alarming number of more than 11,000 probing machines and 300 DDoS attack victims hosted by critical sectors. We also generate rare insights related to the maliciousness of various business sectors, including financial, which typically do not report their hosted and targeted illicit activities for reputation-preservation purposes. While we treat the obtained results with strict confidence due to obvious sensitivity reasons, we postulate that such generated cyber threat intelligence could be shared with sector/critical infrastructure operators, backbone networks and Internet service providers to contribute to the overall threat remediation objective.
登录
查看更多内容
DOI:
10.1007/978-3-030-46908-5_2
发表时间:
2020
期刊:
Advanced Sciences and Technologies for Security Applications
影响因子:
--
作者:
S. Rass;S. Schauer;Sandra König;Quanyan Zhu
通讯作者:
S. Rass;S. Schauer;Sandra König;Quanyan Zhu
DOI:
--
发表时间:
2014
期刊:
39th Annual IEEE Conference on Local Computer Networks Workshops
影响因子:
--
作者:
Eray Balkanli;Nur Zincir
通讯作者:
Nur Zincir
DOI:
--
发表时间:
2017
期刊:
ARES
影响因子:
--
作者:
Norbert Blenn;Vincent Ghiëtte;C. Doerr
通讯作者:
C. Doerr
影响因子:
35.6
作者:
Claude Fachkha;M. Debbabi
通讯作者:
M. Debbabi
DOI:
--
发表时间:
2015
期刊:
IEEE Conference on Communications and Network Security
影响因子:
--
作者:
Emmanouil Vasilomanolakis;Shreyas Srinivasa;M. Mühlhäuser
通讯作者:
M. Mühlhäuser