Analyzing darknet TCP traffic stability at different timescales

Napaphat Vichaidis, H. Tsunoda, G. Keeni
{"title":"Analyzing darknet TCP traffic stability at different timescales","authors":"Napaphat Vichaidis, H. Tsunoda, G. Keeni","doi":"10.1109/ICOIN.2018.8343098","DOIUrl":null,"url":null,"abstract":"Darknet traffic analysis is a possible choice for observing global trends in security threats and analyzing the behavior of Internet attacks. We previously analyzed darknet traffic and evaluated the day to day stability. The investigation of traffic data identifies several anomalous events with drastic changes in instability mainly caused by distributed denial-of-service attacks, misconfigurations, scans, and backscatters. Our previous proposal is not adapted to detect small-scale events, where a small number of attackers send packets to the destination targets in a short duration. We analyze herein the cause of instabilities in transmission control protocol traffic at different timescales by investigating the number of senders to each destination port and the duration of the attack to classify the characteristics of diverse events. Some large-scale events can be detected from the instabilities in daily traffic, while some small-scale events can be detected from the instabilities of hourly traffic.","PeriodicalId":228799,"journal":{"name":"2018 International Conference on Information Networking (ICOIN)","volume":"27 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"1900-01-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"3","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2018 International Conference on Information Networking (ICOIN)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICOIN.2018.8343098","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 3

Abstract

Darknet traffic analysis is a possible choice for observing global trends in security threats and analyzing the behavior of Internet attacks. We previously analyzed darknet traffic and evaluated the day to day stability. The investigation of traffic data identifies several anomalous events with drastic changes in instability mainly caused by distributed denial-of-service attacks, misconfigurations, scans, and backscatters. Our previous proposal is not adapted to detect small-scale events, where a small number of attackers send packets to the destination targets in a short duration. We analyze herein the cause of instabilities in transmission control protocol traffic at different timescales by investigating the number of senders to each destination port and the duration of the attack to classify the characteristics of diverse events. Some large-scale events can be detected from the instabilities in daily traffic, while some small-scale events can be detected from the instabilities of hourly traffic.
分析暗网TCP流量在不同时间尺度下的稳定性
暗网流量分析是观察全球安全威胁趋势和分析网络攻击行为的一种可能选择。我们之前分析了暗网流量并评估了日常稳定性。对流量数据的调查发现了几个异常事件,这些事件的不稳定性变化主要是由分布式拒绝服务攻击、错误配置、扫描和反向散射引起的。我们之前的建议不适合检测小规模事件,即少数攻击者在短时间内向目的目标发送数据包。本文通过调查每个目的端口的发送方数量和攻击持续时间,分析了不同时间尺度下传输控制协议流量不稳定的原因,对不同事件的特征进行了分类。一些大规模的事件可以从日常流量的不稳定中检测出来,而一些小规模的事件可以从小时流量的不稳定中检测出来。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信