• DocumentCode
    248578
  • Title

    Towards a taxonomy of darknet traffic

  • Author

    Jun Liu ; Fukuda, Kenji

  • Author_Institution
    Dept. of Inf., Grad. Univ. for Adv. Studies, Tokyo, Japan
  • fYear
    2014
  • fDate
    4-8 Aug. 2014
  • Firstpage
    37
  • Lastpage
    43
  • Abstract
    Darknets can be used to monitor unexpected network traffic destined for allocated but unused IP address blocks, thus providing an effective traffic measurement technique for viewing certain remote network security events. Past works in this field discussed the possible causes (events) of darknet traffic and applied their classification schemes on short-range traces. Our interest lies, however, in how darknets have evolved since those works and the effectiveness of a darknet taxonomy for real long-range traffic. We thus propose a simple but effective taxonomy of darknet traffic, on the basis of observations, and evaluate it on real darknet traces covering six years. The evaluation results show that we can detect and label anomalous events defined by the taxonomy for over 96% of all sources, making the unlabeled source rate extremely low. We also obtain some interesting findings on the evolution of different anomalous events since 2006 (especially in recent years), determine the most appropriate time bin for traffic analysis of our traces, and highlight the general applicability of our taxonomy on different darknet datasets. Finally, we conclude that most sources in our traces are characterized by just one or two events with simple attack mechanisms.
  • Keywords
    IP networks; telecommunication security; telecommunication traffic; anomalous events; darknet datasets; darknet taxonomy; darknet traffic; real long-range traffic; remote network security events; short-range traces; time bin; traffic analysis; traffic measurement technique; unexpected network traffic; unlabeled source rate; unused IP address blocks; Backscatter; IP networks; Internet; Monitoring; Ports (Computers); Protocols; Taxonomy; Darknet; Taxonomy; Traffic Analysis;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Wireless Communications and Mobile Computing Conference (IWCMC), 2014 International
  • Conference_Location
    Nicosia
  • Print_ISBN
    978-1-4799-7324-8
  • Type

    conf

  • DOI
    10.1109/IWCMC.2014.6906329
  • Filename
    6906329