• DocumentCode
    3043304
  • Title

    Darknet Monitoring on Real-Operated Networks

  • Author

    Mizoguchi, Seiichiro ; Fukushima, Yoshiro ; Kasahara, Yoshiaki ; Hori, Yoshiaki ; Sakurai, Kouichi

  • Author_Institution
    Kyushu Univ., Fukuoka, Japan
  • fYear
    2010
  • fDate
    4-6 Nov. 2010
  • Firstpage
    278
  • Lastpage
    285
  • Abstract
    Dark net monitoring is an effective method to analyze malicious activities on networks including the Internet. Since there is no legitimate host on darknets, traffic sent to such a space is considered to be malicious. There are two major issues for dark net monitoring: how to prepare unused address space and how to configure network sensors deployed on the network. Preparation of monitoring addresses is difficult, and it have not been obvious yet what an appropriate configuration is. To solve the first issue, we proposed a method for network monitoring by exploiting unused IP addresses on segments managed by DHCP server, where is a real-operated network. By assigning these addresses, we can easily obtain IP addresses for monitoring and enable network monitoring on production network. Furthermore, we conducted real dark net monitoring experiments and clarified what kind of information could be obtained. We deployed several types of sensors on real-operated network and captured dark net traffic. After analyzing the traffic, we compared the data between each sensor. We found that there were dramatic differences between the data collected by each sensor and our proposed method was useful for real network monitoring.
  • Keywords
    Internet; computer network security; invasive software; IP address; Internet; dark net monitoring; malicious activity detection; real-operated network monitoring; Broadband communication; Wireless communication; darknet monitoring; real-operated network;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Broadband, Wireless Computing, Communication and Applications (BWCCA), 2010 International Conference on
  • Conference_Location
    Fukuoka
  • Print_ISBN
    978-1-4244-8448-5
  • Electronic_ISBN
    978-0-7695-4236-2
  • Type

    conf

  • DOI
    10.1109/BWCCA.2010.82
  • Filename
    5633172