Darknet monitoring on real-operated networks

Seiichiro Mizoguchi, Yoshiro Fukushima, Yoshiaki Kasahara, Yoshiaki Hori, Kouichi Sakurai

研究成果: Chapter in Book/Report/Conference proceedingConference contribution

1 被引用数 (Scopus)

抄録

Darknet monitoring is an effective method to analyze malicious activities on networks including the Internet. Since there is no legitimate host on darknets, traffic sent to such a space is considered to be malicious. There are two major issues for darknet monitoring: how to prepare unused address space and how to configure network sensors deployed on the network. Preparation of monitoring addresses is difficult, and it have not been obvious yet what an appropriate configuration is. To solve the first issue, we proposed a method for network monitoring by exploiting unused IP addresses on segments managed by DHCP server, where is a real-operated network. By assigning these addresses, we can easily obtain IP addresses for monitoring and enable network monitoring on production network. Furthermore, we conducted real darknet monitoring experiments and clarified what kind of information could be obtained. We deployed several types of sensors on real-operated network and captured darknet traffic. After analyzing the traffic, we compared the data between each sensor. We found that there were dramatic differences between the data collected by each sensor and our proposed method was useful for real network monitoring.

本文言語英語
ホスト出版物のタイトルProceedings - 2010 International Conference on Broadband, Wireless Computing Communication and Applications, BWCCA 2010
ページ278-285
ページ数8
DOI
出版ステータス出版済み - 2010
イベント5th International Conference on Broadband Wireless Computing, Communication and Applications, BWCCA 2010 - Fukuoka, 日本
継続期間: 11 4 201011 6 2010

その他

その他5th International Conference on Broadband Wireless Computing, Communication and Applications, BWCCA 2010
国/地域日本
CityFukuoka
Period11/4/1011/6/10

All Science Journal Classification (ASJC) codes

  • コンピュータ ネットワークおよび通信
  • コンピュータ サイエンスの応用

フィンガープリント

「Darknet monitoring on real-operated networks」の研究トピックを掘り下げます。これらがまとまってユニークなフィンガープリントを構成します。

引用スタイル