Analysis of internet-wide probing using darknets

Analysis of internet-wide probing using darknets
复制标题

使用暗网进行互联网范围内的探测分析

DOI:
--
复制
发表时间:
2012
期刊:
BADGERS@CCS
影响因子:
--
通讯作者:
K. Claffy
K. Claffy
中科院分区:
--
文献类型:
--
作者:
A. Dainotti;Alistair King;K. Claffy

文献摘要

被引文献

相似文献

最近对到达 UCSD 网络望远镜(/8 暗网)的流量进行的分析揭示了一个复杂的僵尸网络扫描事件,该事件在大约 12 天内秘密扫描了整个 IPv4 空间。我们只是在研究完全不相关的行为(2011 年 2 月埃及的审查事件)时偶然发现了这一事件,但我们仔细研究了扫描,包括验证我们的观察结果,并将其与其他人共享的其他大型数据集进行交叉关联。我们希望扩展这些策略来检测其他大规模恶意事件。我们怀疑,对抗恶意软件的斗争将大大受益(并且可能需要)各种大规模安全相关数据集的协作共享。我们希望在研讨会上讨论这一挑战的技术和数据共享政策方面。
Recent analysis of traffic reaching the UCSD Network Telescope (a /8 darknet) revealed a sophisticated botnet scanning event that covertly scanned the entire IPv4 space in about 12 days. We only serendipitously discovered this event while studying a completely unrelated behavior (censorship episode in Egypt in February 2011), but we carefully studied the scan, including validating and cross-correlating our observations with other large data set shared by others. We would like to extend these strategies to detect other large-scale malicious events. We suspect the fight against malware will benefit greatly (and perhaps require) collaborative sharing of diverse large-scale security-related data sets. We hope to discuss both the technical and the data-sharing policy aspects of this challenge at the workshop.