DScope: A Cloud-Native Internet Telescope

DScope: A Cloud-Native Internet Telescope
复制标题

DOI:
--
复制
发表时间:
2023
期刊:
--
影响因子:
--
通讯作者:
Eric Pauley;P. Barford;P. Mcdaniel
Eric Pauley;P. Barford;P. Mcdaniel
中科院分区:
其他
文献类型:
--
作者:
Eric Pauley;P. Barford;P. Mcdaniel

文献摘要

相似文献

来自互联网望远镜的数据监视路由但未使用的IP地址空间,这些数据已经成为无数关于恶意、不必要和意外行为的见解的基础。然而,业务向云基础设施的迁移和IPv4地址空间的日益稀缺对传统的互联网望远镜提出了严峻的挑战。DS COPE是一种基于云的互联网望远镜,具有可扩展性和交互性。我们描述了DS COPE的设计和实现,它包括两个主要部分。收集器部署在云虚拟机上,与传入的连接请求交互,并捕获pcap痕迹。数据处理管道对来自已部署收集器的pcap进行组织、转换和存档,以便进行事后分析。在将DS COPE收集的流量样本与传统望远镜的流量样本进行比较时,我们看到了针对云系统行为的数量和现象的显著差异,在随机扫描下,云目标的数量高达预期的450倍。我们还表明,DS COPE的自适应方法实现了令人印象深刻的性价比:在给定IP地址上,在不到8分钟的观察时间内实现了扫描仪的最佳产量。我们的研究结果表明,基于云的望远镜比传统技术获得了更广泛、更全面的视角。
Data from Internet telescopes that monitor routed but unused IP address space has been the basis for myriad insights on malicious, unwanted, and unexpected behavior. However, service migration to cloud infrastructure and the increasing scarcity of IPv4 address space present serious challenges to traditional Internet telescopes. This paper describes DS COPE , a cloud-based Internet telescope designed to be scalable and interactive. We describe the design and implementation of DS COPE , which includes two major components. Collectors are deployed on cloud VMs, interact with incoming connection requests, and capture pcap traces. The data processing pipeline organizes, transforms, and archives the pcap s from deployed collectors for post-facto analysis. In comparing a sampling of DS COPE ’s collected traffic with that of a traditional telescope, we see a striking difference in both the quantity and phenomena of behavior targeting cloud systems, with up to 450 × as much cloud-targeting as expected under random scanning. We also show that DS COPE ’s adaptive approach achieves impressive price performance: optimal yield of scanners on a given IP address is achieved in under 8 minutes of observation. Our results demonstrate that cloud-based telescopes achieve a significantly broader and more comprehensive perspective than traditional techniques.