DocumentCode :
248578
Title :
Towards a taxonomy of darknet traffic
Author :
Jun Liu ; Fukuda, Kenji
Author_Institution :
Dept. of Inf., Grad. Univ. for Adv. Studies, Tokyo, Japan
fYear :
2014
fDate :
4-8 Aug. 2014
Firstpage :
37
Lastpage :
43
Abstract :
Darknets can be used to monitor unexpected network traffic destined for allocated but unused IP address blocks, thus providing an effective traffic measurement technique for viewing certain remote network security events. Past works in this field discussed the possible causes (events) of darknet traffic and applied their classification schemes on short-range traces. Our interest lies, however, in how darknets have evolved since those works and the effectiveness of a darknet taxonomy for real long-range traffic. We thus propose a simple but effective taxonomy of darknet traffic, on the basis of observations, and evaluate it on real darknet traces covering six years. The evaluation results show that we can detect and label anomalous events defined by the taxonomy for over 96% of all sources, making the unlabeled source rate extremely low. We also obtain some interesting findings on the evolution of different anomalous events since 2006 (especially in recent years), determine the most appropriate time bin for traffic analysis of our traces, and highlight the general applicability of our taxonomy on different darknet datasets. Finally, we conclude that most sources in our traces are characterized by just one or two events with simple attack mechanisms.
Keywords :
IP networks; telecommunication security; telecommunication traffic; anomalous events; darknet datasets; darknet taxonomy; darknet traffic; real long-range traffic; remote network security events; short-range traces; time bin; traffic analysis; traffic measurement technique; unexpected network traffic; unlabeled source rate; unused IP address blocks; Backscatter; IP networks; Internet; Monitoring; Ports (Computers); Protocols; Taxonomy; Darknet; Taxonomy; Traffic Analysis;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Wireless Communications and Mobile Computing Conference (IWCMC), 2014 International
Conference_Location :
Nicosia
Print_ISBN :
978-1-4799-7324-8
Type :
conf
DOI :
10.1109/IWCMC.2014.6906329
Filename :
6906329
Link To Document :
بازگشت