DocumentCode
248578
Title
Towards a taxonomy of darknet traffic
Author
Jun Liu ; Fukuda, Kenji
Author_Institution
Dept. of Inf., Grad. Univ. for Adv. Studies, Tokyo, Japan
fYear
2014
fDate
4-8 Aug. 2014
Firstpage
37
Lastpage
43
Abstract
Darknets can be used to monitor unexpected network traffic destined for allocated but unused IP address blocks, thus providing an effective traffic measurement technique for viewing certain remote network security events. Past works in this field discussed the possible causes (events) of darknet traffic and applied their classification schemes on short-range traces. Our interest lies, however, in how darknets have evolved since those works and the effectiveness of a darknet taxonomy for real long-range traffic. We thus propose a simple but effective taxonomy of darknet traffic, on the basis of observations, and evaluate it on real darknet traces covering six years. The evaluation results show that we can detect and label anomalous events defined by the taxonomy for over 96% of all sources, making the unlabeled source rate extremely low. We also obtain some interesting findings on the evolution of different anomalous events since 2006 (especially in recent years), determine the most appropriate time bin for traffic analysis of our traces, and highlight the general applicability of our taxonomy on different darknet datasets. Finally, we conclude that most sources in our traces are characterized by just one or two events with simple attack mechanisms.
Keywords
IP networks; telecommunication security; telecommunication traffic; anomalous events; darknet datasets; darknet taxonomy; darknet traffic; real long-range traffic; remote network security events; short-range traces; time bin; traffic analysis; traffic measurement technique; unexpected network traffic; unlabeled source rate; unused IP address blocks; Backscatter; IP networks; Internet; Monitoring; Ports (Computers); Protocols; Taxonomy; Darknet; Taxonomy; Traffic Analysis;
fLanguage
English
Publisher
ieee
Conference_Titel
Wireless Communications and Mobile Computing Conference (IWCMC), 2014 International
Conference_Location
Nicosia
Print_ISBN
978-1-4799-7324-8
Type
conf
DOI
10.1109/IWCMC.2014.6906329
Filename
6906329
Link To Document