DocumentCode :
624830
Title :
A baseline study of potentially malicious activity across five network telescopes
Author :
Irwin, Barry
Author_Institution :
Dept. of Comput. Sci., Rhodes Univ., Grahamstown, South Africa
fYear :
2013
fDate :
4-7 June 2013
Firstpage :
1
Lastpage :
17
Abstract :
This paper explores the Internet Background Radiation (IBR) observed across five distinct network telescopes over a 15 month period. These network telescopes consisting of a /24 netblock each and are deployed in IP space administered by TENET, the tertiary education network in South Africa covering three numerically distant /8 network blocks. The differences and similarities in the observed network traffic are explored. Two anecdotal case studies are presented relating to the MS08-067 and MS12-020 vulnerabilities in the Microsoft Windows platforms. The first of these is related to the Conficker worm outbreak in 2008, and traffic targeting 445/tcp remains one of the top constituents of IBR as observed on the telescopes. The case of MS12-020 is of interest, as a long period of scanning activity targeting 3389/tcp, used by the Microsoft RDP service, was observed, with a significant drop on activity relating to the release of the security advisory and patch. Other areas of interest are highlighted, particularly where correlation in scanning activity was observed across the sensors. The paper concludes with some discussion on the application of network telescopes as part of a cyber-defence solution.
Keywords :
Internet; computer network security; invasive software; operating systems (computers); IBR; IP space; Internet background radiation; MS08-067; MS12-020; Microsoft RDP service; Microsoft Windows platforms; South Africa; TENET; conficker worm outbreak; cyber-defence solution; netblock; network telescopes; network traffic; potentially malicious activity; tertiary education network; Grippers; IP networks; Internet; Monitoring; Security; Sensors; Telescopes; darknet; internet radiations; network telescope; scanning;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Cyber Conflict (CyCon), 2013 5th International Conference on
Conference_Location :
Tallinn
ISSN :
2325-5366
Print_ISBN :
978-1-4799-0450-1
Type :
conf
Filename :
6568378
Link To Document :
بازگشت