• DocumentCode
    1875229
  • Title

    Comparative analysis of darknet traffic characteristics between darknet sensors

  • Author

    Gadhia, Falguni ; Jangwon Choi ; Buseung Cho ; Jungsuk Song

  • Author_Institution
    Korea Univ. of Sci. & Technol., Daejeon, South Korea
  • fYear
    2015
  • fDate
    1-3 July 2015
  • Firstpage
    59
  • Lastpage
    64
  • Abstract
    Today, Internet is incessantly attacked by wide variety of network-based threats. One of the ways to monitor or identify such prevailing threats is to monitor incoming traffic to unused network addresses popularly known as darknet and often also referred with various other names like network telescope or black hole. As, all the traffic arriving at darknet is mainly the result from malicious probing or mis configuration in the network. It is expected that to have similar incoming traffic behaviour across different darknet sensors, however, various studies found it different. Various reason cited behind it is misconfiguration, certain kind of attack, difference in filtering parameter or system configuration itself. However, concrete reason beside this is still missing. In this regard, to get further understanding, in this study, we performed deeper comparative analysis between two darknet sensors (KISTI Darknet network) that are differently located but have similar filtering and system configuration. Comparative analysis considering total incoming packet, number of source host, targeting destination port and protocol revealed that there exists wide difference in incoming traffic characteristics between the darknet sensors. Moreover, for TCP and UDP comparison, UDP traffic showed more targeting behaviour to particular darknet block (difference in traffic characteristics between darknet sensors), in contrast to it, TCP traffic showed more scanning behaviour (similarity in traffic characteristics between darknet sensor).
  • Keywords
    Internet; black holes; filtering theory; sensors; telecommunication security; telecommunication traffic; transport protocols; Internet; KISTI darknet network; TCP traffic; UDP traffic; black hole; darknet block; darknet sensors; darknet traffic characteristics; destination port; filtering parameter; network addresses; network telescope; network-based threats; protocol; source host; Filtering; Internet; Monitoring; Ports (Computers); Protocols; Sensor phenomena and characterization; Darknet; TCP; UDP; network monitoring; network security;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Advanced Communication Technology (ICACT), 2015 17th International Conference on
  • Conference_Location
    Seoul
  • Print_ISBN
    978-8-9968-6504-9
  • Type

    conf

  • DOI
    10.1109/ICACT.2015.7224757
  • Filename
    7224757