Darknet as a Source of Cyber Intelligence: Survey, Taxonomy, and Characterization

Darknet as a Source of Cyber Intelligence: Survey, Taxonomy, and Characterization
复制标题

暗网作为网络情报的来源:调查、分类和表征

DOI:
--
复制
发表时间:
2016
影响因子:
35.6
通讯作者:
M. Debbabi
M. Debbabi
中科院分区:
计算机科学1区
文献类型:
--
作者:
Claude Fachkha;M. Debbabi

文献摘要

被引文献

相似文献

今天,互联网安全社区在很大程度上强调网络空间监控,以生成网络情报。在本文中,我们对暗网进行了调查。后者是通过被动监测观察互联网活动和网络攻击的有效方法。我们主要定义和描述暗网,并指出其替代名称。我们进一步列出了其他基于陷阱的监控系统,并将其与暗网进行比较。此外,为了提供对暗网信息的现实测量和分析,我们报告了案例研究,即2008年和2009年的Conficker蠕虫,2011年的Sality SIP扫描僵尸网络,以及2014年最大的放大攻击。最后,我们提供了与暗网技术相关的分类,并确定了与三个主要暗网类别相关的研究差距:部署,流量分析和可视化。暗网项目被发现监测各种网络威胁活动,分布在全球三分之一的互联网上。我们进一步确定Honeyd可能是实现暗网传感器的最实用工具,未来暗网的部署将包括基于移动的VOIP技术。此外,就暗网分析而言,计算机蠕虫和扫描活动被认为是整个暗网中最常见的威胁;红色代码和Slammer/Sapphire是分析最多的蠕虫。此外,我们的研究揭示了暗网研究中的各种不足。例如,不到1%的贡献解决了分布式反射拒绝服务(DRDoS)放大调查,最多2%的研究工作确定了欺骗活动。最后但并非最不重要的是,我们的调查确定了特定的暗网领域,例如IPv6暗网,事件监控和游戏引擎可视化方法,这些领域需要研究界给予更多的关注。
Today, the Internet security community largely emphasizes cyberspace monitoring for the purpose of generating cyber intelligence. In this paper, we present a survey on darknet. The latter is an effective approach to observe Internet activities and cyber attacks via passive monitoring. We primarily define and characterize darknet and indicate its alternative names. We further list other trap-based monitoring systems and compare them to darknet. Moreover, in order to provide realistic measures and analysis of darknet information, we report case studies, namely, Conficker worm in 2008 and 2009, Sality SIP scan botnet in 2011, and the largest amplification attack in 2014. Finally, we provide a taxonomy in relation to darknet technologies and identify research gaps that are related to three main darknet categories: deployment, traffic analysis, and visualization. Darknet projects are found to monitor various cyber threat activities and are distributed in one third of the global Internet. We further identify that Honeyd is probably the most practical tool to implement darknet sensors, and future deployment of darknet will include mobile-based VOIP technology. In addition, as far as darknet analysis is considered, computer worms and scanning activities are found to be the most common threats that can be investigated throughout darknet; Code Red and Slammer/Sapphire are the most analyzed worms. Furthermore, our study uncovers various lacks in darknet research. For instance, less than 1% of the contributions tackled distributed reflection denial of service (DRDoS) amplification investigations, and at most 2% of research works pinpointed spoofing activities. Last but not least, our survey identifies specific darknet areas, such as IPv6 darknet, event monitoring, and game engine visualization methods that require a significantly greater amount of attention from the research community.