【24h】

Comparative analysis of darknet traffic characteristics between darknet sensors

机译:暗网传感器之间的暗网流量特性比较分析

获取原文
获取原文并翻译 | 示例

摘要

Today, Internet is incessantly attacked by wide variety of network-based threats. One of the ways to monitor or identify such prevailing threats is to monitor incoming traffic to unused network addresses popularly known as darknet and often also referred with various other names like network telescope or black hole. As, all the traffic arriving at darknet is mainly the result from malicious probing or mis configuration in the network. It is expected that to have similar incoming traffic behaviour across different darknet sensors, however, various studies found it different. Various reason cited behind it is misconfiguration, certain kind of attack, difference in filtering parameter or system configuration itself. However, concrete reason beside this is still missing. In this regard, to get further understanding, in this study, we performed deeper comparative analysis between two darknet sensors (KISTI Darknet network) that are differently located but have similar filtering and system configuration. Comparative analysis considering total incoming packet, number of source host, targeting destination port and protocol revealed that there exists wide difference in incoming traffic characteristics between the darknet sensors. Moreover, for TCP and UDP comparison, UDP traffic showed more targeting behaviour to particular darknet block (difference in traffic characteristics between darknet sensors), in contrast to it, TCP traffic showed more scanning behaviour (similarity in traffic characteristics between darknet sensor).
机译:如今,Internet不断受到各种基于网络的威胁的攻击。监视或识别此类主要威胁的方法之一是监视到未使用的网络地址的传入流量,该网络地址通常称为Darknet,并且经常还会用其他各种名称(如网络望远镜或黑洞)来指代。因此,到达暗网的所有流量主要是由于恶意探测或网络中配置错误所致。可以预期,在不同的暗网传感器之间会有类似的传入流量行为,但是,各种研究发现它都不同。它背后引用的各种原因是配置错误,某种攻击,过滤参数或系统配置本身的差异。但是,除此之外的具体原因仍然缺失。在这方面,为了获得进一步的了解,在本研究中,我们在位置不同但具有相似过滤和系统配置的两个暗网传感器(KISTI暗网网络)之间进行了更深入的比较分析。考虑到总传入数据包,源主机数量,目标目的地端口和协议的比较分析表明,暗网传感器之间的传入流量特性存在很大差异。此外,对于TCP和UDP比较,UDP流量显示出对特定暗网块的更多定向行为(暗网传感器之间的流量特性差异),与此相反,TCP流量显示出更多的扫描行为(暗网传感器之间的流量特性相似)。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号