首页> 外文会议>International Workshop on Traffic Monitoring and Analysis >How Dangerous Is Internet Scanning? A Measurement Study of the Aftermath of an Internet-Wide Scan
【24h】

How Dangerous Is Internet Scanning? A Measurement Study of the Aftermath of an Internet-Wide Scan

机译:互联网扫描有多危险?互联网范围扫描后的测量研究

获取原文

摘要

Internet scanning is a de facto background traffic noise that is not clear if it poses a dangerous threat, i.e., what happens to scanned hosts? what is the success rate of scanning? and whether the problem is worth investing significant effort and money on mitigating it, e.g., by filtering unwanted traffic? In this work we take a first look into Internet scanning from the point of view of scan repliers using a unique combination of data sets which allows us to estimate how many hosts replied to scanners and whether they were subsequently attacked in an actual network. To contain our analysis, we focus on a specific interesting scanning event that was orchestrated by the Sality botnet during February 2011 which scanned the entire IPv4 address space. By analyzing unsampled NetFlow records, we show that 2% of the scanned hosts actually replied to the scanners. Moreover, by correlating scan replies with IDS alerts from the same network, we show that significant exploitation activity followed towards the repliers, which eventually led to an estimated 8% of compromised repliers. These observations suggest that Internet scanning is dangerous: in our university network, at least 142 scanned hosts were eventually compromised. World-wide, the number of hosts that were compromised in response to the studied event is likely much larger.
机译:互联网扫描是一个事实上的背景流量噪音,如果它造成危险的威胁,即扫描主机会发生什么?扫描的成功率是多少?是否值得投资重大努力和金钱,例如,通过过滤不需要的流量?在这项工作中,我们使用允许我们估计扫描仪回复的主机以及它们是否随后在实际网络中攻击的互联网扫描从扫描副本的角度来看互联网扫描。为了包含我们的分析,我们专注于由Sality Botnet在2011年2月策划的特定有趣的扫描事件,该事件扫描了整个IPv4地址空间。通过分析Unspled NetFlow记录,我们显示2%的扫描主机实际上回复了扫描仪。此外,通过将扫描回复与来自同一网络的ID警报相关联,我们显示出于复制器的显着开发活动,最终导致估计的8%受损复制。这些观察结果表明,互联网扫描是危险的:在我们的大学网络中,至少142个扫描的主机最终受到损害。全世界,因研究所研究的事件而受到损害的主机数量可能更大。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号