• DocumentCode
    3517547
  • Title

    Experiences and Observations from the NoAH Infrastructure

  • Author

    Kontaxis, Georgios ; Polakis, Iasonas ; Antonatos, Spiros ; Markatos, Evangelos P.

  • Author_Institution
    Inst. of Comput. Sci., Found. for Res. & Technol. Hellas, Heraklion, Greece
  • fYear
    2010
  • fDate
    28-29 Oct. 2010
  • Firstpage
    11
  • Lastpage
    18
  • Abstract
    Monitoring large chunks of unused IP address space yields interesting observations and useful results. However, the volume and diversity of the collected data makes the extraction of information a challenging task. Additionally, the maintenance of the monitoring infrastructure is another demanding and time-consuming effort. To overcome these problems, we present several visualization techniques that enable users to observe what happens in their unused address space over arbitrary time periods and provide the necessary tools for administrators to monitor their infrastructure. Our approach, which is based on open-source standard technologies, transforms the raw information at the network level and provides a customized and Web-accessible view. In this paper, we present the design, implementation and early experiences of the visualization techniques and tools deployed for the NoAH project, a large-scale honey pot-based infrastructure. Additionally, we provide a traffic analysis of data collected over a six month period of our infrastructure´s operation. During the data collection period, we observed that the number of attackers continually increased as did the volume of traffic they generated. Furthermore, interesting patterns for specific types of traffic have been identified, such as the diurnal cycle of the traffic targeting TCP port 445 (Windows Directory Services), the port that receives the largest volume of attack traffic.
  • Keywords
    IP networks; Internet; computer network security; data visualisation; information retrieval; public domain software; telecommunication traffic; IP address; NoAH infrastructure; Web-accessible view; information extraction; large-scale honeypot-based infrastructure; open-source standard technology; traffic analysis; visualization technique; Availability; Data visualization; Grippers; IP networks; Monitoring; Sensors; Servers;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computer Network Defense (EC2ND), 2010 European Conference on
  • Conference_Location
    Berlin
  • Print_ISBN
    978-1-4244-9377-7
  • Type

    conf

  • DOI
    10.1109/EC2ND.2010.12
  • Filename
    5663312