首页> 外文会议>International Conference on Passive and Active Measurement >Clairvoyance: Inferring Blocklist Use on the Internet
【24h】

Clairvoyance: Inferring Blocklist Use on the Internet

机译:Clairvoyance:推断互联网上的块列表使用

获取原文

摘要

One of the staples of network defense is blocking traffic to and from a list of "known bad" sites on the Internet. However, few organizations are in a position to produce such a list themselves, so pragmatically this approach depends on the existence of third-party "threat intelligence" providers who specialize in distributing feeds of unwelcome IP addresses. However, the choice to use such a strategy, let alone which data feeds are trusted for this purpose, is rarely made public and thus little is understood about the deployment of these techniques in the wild. To explore this issue, we have designed and implemented a technique to infer proactive traffic blocking on a remote host and, through a series of measurements, to associate that blocking with the use of particular IP blocklists. In a pilot study of 220K US hosts, we find as many as one fourth of the hosts appear to blocklist based on some source of threat intelligence data, and about 2% use one of the 9 particular third-party blocklists that we evaluated.
机译:网络防御的一个钉钉是阻止互联网上的“已知糟糕”站点的流量。然而,很少有组织能够在一个职位上制作这样的列表本身,因此这种方法取决于专门分配不受欢迎的IP地址的饲料的第三方“威胁情报”提供者的存在。然而,选择使用这种策略的选择,更不用说数据源是为了此目的而信赖的,很少被公开,因此很少被理解在野外这些技术部署。要探索此问题,我们已经设计并实现了一种在远程主机上推断出推断的技术,并通过一系列测量来推断出与使用特定IP块列表的阻塞联系。在220k美国主机的试验研究中,我们发现多个主机出现在威胁情报数据的某些来源中的一个四分之一,以及我们评估的9个特定的第三方块列表中的一个大约2%。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号