识别和区分网络流量中的公认扫描器

Michael Patrick Collins, Alefiya Hussain, S. Schwab
{"title":"识别和区分网络流量中的公认扫描器","authors":"Michael Patrick Collins, Alefiya Hussain, S. Schwab","doi":"10.1109/EuroSPW59978.2023.00069","DOIUrl":null,"url":null,"abstract":"Acknowledged scanners are Internet scanners which engage with the community as a whole through, at the minimum through a public website. These scanners may provide a service, whether as an education institution, corporation, nonprofit or other organization and may engage in good citizen behaviors such as opt–out lists and by publishing their sources. In this paper, we describe the behavior and population of acknowledged scanners and demonstrate the difference between acknowledged scanners and other (unacknowledged) scanners. We quantitatively show acknowledged scanners, scan from a limited set of addresses, scan predictably, and most importantly the ports (and assumed vulnerabilities) that they scan for differ significantly from the targets of unacknowledged scanners. Failing to differentiate acknowledged and unacknowledged scanners impacts both research and operations, calling into question research results categorizing scanners and overloading operators in false positives. We show the differences between these two scanner classes based on a 30 day sample of darkspace data collected from the USC-ISI network that can be widely shared. We have also maintained an open access acknowledged scanner repository, a whitelist of 40+ acknowledged scanner entities and their IP addresses for the last three years. These acknowledged scanners are researchers, internet public health organizations, and threat intelligence companies. More than 12 unique security organizations track the whitelist to include into their threat assessments.","PeriodicalId":220415,"journal":{"name":"2023 IEEE European Symposium on Security and Privacy Workshops (EuroS&PW)","volume":"1 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2023-07-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":"{\"title\":\"Identifying and Differentiating Acknowledged Scanners in Network Traffic\",\"authors\":\"Michael Patrick Collins, Alefiya Hussain, S. Schwab\",\"doi\":\"10.1109/EuroSPW59978.2023.00069\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Acknowledged scanners are Internet scanners which engage with the community as a whole through, at the minimum through a public website. These scanners may provide a service, whether as an education institution, corporation, nonprofit or other organization and may engage in good citizen behaviors such as opt–out lists and by publishing their sources. In this paper, we describe the behavior and population of acknowledged scanners and demonstrate the difference between acknowledged scanners and other (unacknowledged) scanners. We quantitatively show acknowledged scanners, scan from a limited set of addresses, scan predictably, and most importantly the ports (and assumed vulnerabilities) that they scan for differ significantly from the targets of unacknowledged scanners. Failing to differentiate acknowledged and unacknowledged scanners impacts both research and operations, calling into question research results categorizing scanners and overloading operators in false positives. We show the differences between these two scanner classes based on a 30 day sample of darkspace data collected from the USC-ISI network that can be widely shared. We have also maintained an open access acknowledged scanner repository, a whitelist of 40+ acknowledged scanner entities and their IP addresses for the last three years. These acknowledged scanners are researchers, internet public health organizations, and threat intelligence companies. More than 12 unique security organizations track the whitelist to include into their threat assessments.\",\"PeriodicalId\":220415,\"journal\":{\"name\":\"2023 IEEE European Symposium on Security and Privacy Workshops (EuroS&PW)\",\"volume\":\"1 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2023-07-01\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2023 IEEE European Symposium on Security and Privacy Workshops (EuroS&PW)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/EuroSPW59978.2023.00069\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2023 IEEE European Symposium on Security and Privacy Workshops (EuroS&PW)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/EuroSPW59978.2023.00069","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

摘要

公认的扫描器是Internet扫描器,它至少通过一个公共网站作为一个整体与社区接触。这些扫描仪可能提供服务,无论是作为教育机构,公司,非营利组织或其他组织,并可能参与良好的公民行为,如选择退出名单和公布他们的来源。在本文中,我们描述了已确认扫描器的行为和人口,并演示了已确认扫描器和其他(未确认)扫描器之间的区别。我们定量地显示已确认的扫描器,从有限的地址集进行扫描,可预测地进行扫描,最重要的是,它们扫描的端口(和假定的漏洞)与未确认扫描器的目标有很大的不同。未能区分已识别和未识别的扫描仪会影响研究和操作,导致对扫描仪进行分类的研究结果受到质疑,并导致误报操作人员超载。我们根据USC-ISI网络收集的30天的暗空间数据样本展示了这两种扫描仪类别之间的差异,这些数据可以广泛共享。在过去的三年里,我们还维护了一个开放访问的公认扫描器存储库,一个包含40多个公认扫描器实体及其IP地址的白名单。这些公认的扫描器是研究人员、互联网公共卫生组织和威胁情报公司。超过12个独特的安全组织跟踪白名单,将其纳入威胁评估。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
Identifying and Differentiating Acknowledged Scanners in Network Traffic
Acknowledged scanners are Internet scanners which engage with the community as a whole through, at the minimum through a public website. These scanners may provide a service, whether as an education institution, corporation, nonprofit or other organization and may engage in good citizen behaviors such as opt–out lists and by publishing their sources. In this paper, we describe the behavior and population of acknowledged scanners and demonstrate the difference between acknowledged scanners and other (unacknowledged) scanners. We quantitatively show acknowledged scanners, scan from a limited set of addresses, scan predictably, and most importantly the ports (and assumed vulnerabilities) that they scan for differ significantly from the targets of unacknowledged scanners. Failing to differentiate acknowledged and unacknowledged scanners impacts both research and operations, calling into question research results categorizing scanners and overloading operators in false positives. We show the differences between these two scanner classes based on a 30 day sample of darkspace data collected from the USC-ISI network that can be widely shared. We have also maintained an open access acknowledged scanner repository, a whitelist of 40+ acknowledged scanner entities and their IP addresses for the last three years. These acknowledged scanners are researchers, internet public health organizations, and threat intelligence companies. More than 12 unique security organizations track the whitelist to include into their threat assessments.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信