[Zurück]


Vorträge und Posterpräsentationen (mit Tagungsband-Eintrag):

F. Iglesias Vazquez, T. Zseby:
"Modelling IP darkspace traffic by means of clustering techniques";
Vortrag: Communications and Network Security (CNS), 2014 IEEE Conference on, San Francisco, USA; 29.10.2014 - 31.10.2014; in: "IEEE Conference on Communications and Network Security (CNS)", San Francisco (2014), Paper-Nr. 166-174, 9 S.



Kurzfassung englisch:
An IP darkspace is an unused IP address range. Addresses are announced by routing, but no hosts are attached.

Therefore all traffic directed to IP darkspace addresses is unsolicited and usually originates from attacks, attack preparation activities or misconfigurations. Most of the observed traffic belongs to known phenomena (e.g. horizontal scanning targeting a specific port) and is of limited interest to security analysts. But hidden in the vast amount of common attacks, smaller unusual events may indicate new malicious activities. In this paper we present a methodology to distinguish IP darkspace sources with common traffic patterns from sources that show uncommon behavior and may be the origin of novel attacks. For this, we model IP darkspace sources based on clustering techniques. We extract data from one complete month of a large /8 darkspace capture and use a very simple feature vector. Our analysis is purely based on clustering techniques and does not require any pre-knowledge about phenomena in darkspace traffic. We found that about 75% of the darkspace IP sources contributes to a set of very stable clusters, 4% to less stable clusters and 21% to outliers. This allows us to concentrate the effort for searching for new attacks in just 21% of the sources.

Schlagworte:
network security, darkspace, clustering, traffic analysis


"Offizielle" elektronische Version der Publikation (entsprechend ihrem Digital Object Identifier - DOI)
http://dx.doi.org/10.1109/CNS.2014.6997483

Elektronische Version der Publikation:
http://ieeexplore.ieee.org/xpls/abs_all.jsp?arnumber=6997483&tag=1


Erstellt aus der Publikationsdatenbank der Technischen Universität Wien.