• DocumentCode
    2486731
  • Title

    Investigating the dark cyberspace: Profiling, threat-based analysis and correlation

  • Author

    Fachkha, Claude ; Bou-Harb, Elias ; Boukhtouta, Amine ; Dinh, Son ; Iqbal, Farkhund ; Debbabi, Mourad

  • Author_Institution
    NCFTA Canada & Concordia Inst. for Inf. Syst. Eng., Concordia Univ., Montreal, QC, Canada
  • fYear
    2012
  • fDate
    10-12 Oct. 2012
  • Firstpage
    1
  • Lastpage
    8
  • Abstract
    An effective approach to gather cyber threat intelligence is to collect and analyze traffic destined to unused Internet addresses known as darknets. In this paper, we elaborate on such capability by profiling darknet data. Such information could generate indicators of cyber threat activity as well as providing in-depth understanding of the nature of its traffic. Particularly, we analyze darknet packets distribution, its used transport, network and application layer protocols and pinpoint its resolved domain names. Furthermore, we identify its IP classes and destination ports as well as geo-locate its source countries. We further investigate darknet-triggered threats. The aim is to explore darknet embedded threats and categorize their severities. Finally, we contribute by exploring the inter-correlation of such threats, by applying association rule mining techniques, to build threat association rules. Specifically, we generate clusters of threats that co-occur targeting a specific victim. Such work proves that specific darknet threats are correlated. Moreover, it provides insights about threat patterns and allows the interpretation of threat scenarios.
  • Keywords
    IP networks; Internet; computer network security; data mining; protocols; telecommunication traffic; IP class; Internet address; application layer protocols; association rule mining techniques; cyber threat activity; cyber threat intelligence; dark cyberspace; darknet data profiling; darknet embedded threats; darknet packets distribution; darknet-triggered threats; destination ports; domain names; threat association rules; threat intercorrelation; threat-based analysis; Association rules; Correlation; Cyberspace; IP networks; Internet; Protocols;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Risk and Security of Internet and Systems (CRiSIS), 2012 7th International Conference on
  • Conference_Location
    Cork
  • Print_ISBN
    978-1-4673-3087-9
  • Electronic_ISBN
    978-1-4673-3088-6
  • Type

    conf

  • DOI
    10.1109/CRISIS.2012.6378947
  • Filename
    6378947