首页> 外文会议>Conference on Cyber Sensing >ASN Reputation System Model
【24h】

ASN Reputation System Model

机译:ASN信誉系统模型

获取原文

摘要

Network security monitoring is currently challenged by its reliance on human analysts and the inability for tools to generate indications and warnings for previously unknown attacks. We propose a reputation system based on IP address set membership within the Autonomous System Number (ASN) system. Essentially, a metric generated based on the historic behavior, or misbehavior, of nodes within a given ASN can be used to predict future behavior and provide a mechanism to locate network activity requiring inspection. This will provide reinforcement of notifications and warnings and lead to inspection for ASNs known to be problematic even if initial inspection leads to interpretation of the event as innocuous. We developed proof of concept capabilities to generate the IP address to ASN set membership and analyze the impact of the results. These results clearly show that while some ASNs are one-offs with individual or small numbers of misbehaving IP addresses, there are definitive ASNs with a history of long term and wide spread misbehaving IP addresses. These ASNs with long histories are what we are especially interested in and will provide an additional correlation metric for the human analyst and lead to new tools to aid remediation of these IP address blocks.
机译:网络安全监测目前通过依赖于人类分析师以及工具无法为以前未知的攻击产生指示和警告的工具而挑战。我们提出了一种基于IP地址设置成员资格的声誉系统,在自主系统号(ASN)系统中。基本上,基于给定ASN内的节点的基本生成的度量可以用于预测未来的行为并提供一种机制来定位需要检查的网络活动。这将提供通知和警告的加强,并导致所知道的ASNS的检查是有问题的,即使初始检查导致事件的解释为无害。我们开发了概念功能证明,以为ASN设置成员资格生成IP地址并分析结果的影响。这些结果清楚地表明,虽然某些ASN是具有个人或少量行为行为IP地址的一次性,但具有明确的ASN,具有长期和广泛的行为行为的IP地址历史。这些具有长历史的ASN是我们特别感兴趣的,并将为人类分析师提供额外的相关度量,并导致新工具来帮助修复这些IP地址块。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号