DocumentCode
3347784
Title
Spatial-Temporal Characteristics of Internet Malicious Sources
Author
Zesheng Chen ; Chuanyi Ji ; Barford, Paul
Author_Institution
Florida Int. Univ., Miami
fYear
2008
fDate
13-18 April 2008
Abstract
This paper presents a large scale longitudinal study of the spatial and temporal features of malicious source addresses. The basis of our study is a 402-day trace of over 7 billion Internet intrusion attempts provided by DShield.org, which includes 160 million unique source addresses. Specifically, we focus on spatial distributions and temporal characteristics of malicious sources. First, we find that one out of 27 hosts is potentially a scanning source among 232 IPv4 addresses. We then show that malicious sources have a persistent, non-uniform spatial distribution. That is, more than 80% of the sources send packets from the same 20% of the IPv4 address space over time. We also find that 7.3% of malicious source addresses are unroutable, and that some source addresses are correlated. Next, we show that most sources have a short lifetime. 57.9 % of the source addresses appear only once in the trace, and 90% of source addresses appear less than 5 times. These results have implications for both attacks and defenses.
Keywords
IP networks; Internet; security of data; telecommunication security; IPV4 address; Internet malicious source; spatial-temporal characteristics; Communications Society; Gain measurement; Information filtering; Information filters; Internet; Intrusion detection; Large-scale systems; Network address translation; Paper technology; Telecommunication traffic;
fLanguage
English
Publisher
ieee
Conference_Titel
INFOCOM 2008. The 27th Conference on Computer Communications. IEEE
Conference_Location
Phoenix, AZ
ISSN
0743-166X
Print_ISBN
978-1-4244-2025-4
Type
conf
DOI
10.1109/INFOCOM.2008.299
Filename
4509894
Link To Document