首页> 外文会议>Proceedings of the 1st Network Traffic Measurement and Analysis Conference >Profiling internet scanners: Spatiotemporal structures and measurement ethics
【24h】

Profiling internet scanners: Spatiotemporal structures and measurement ethics

机译:对互联网扫描仪进行概要分析:时空结构和测量伦理

获取原文
获取原文并翻译 | 示例

摘要

Scanning is ubiquitous on the Internet. It assists administrators to troubleshoot their own network, researchers to survey the Internet, and malicious actors to assess the attack surface of targeted networks. As users requirements vary, scans in the wild exhibit very diverse characteristics. For example, the coverage, stealthiness and probing speed are drastically varying from one scanning IP to another. In this paper, we study 15 years of backbone traffic to understand the evolution of mass-scanning tool usage, scanning pattern and the concentration of scanning IPs (also called scanners) in small networks. We also propose a new method to classify scanning IPs' spatial and temporal structure into three profiles that reveal vastly different intent. In particular, we find that 33% of scanners repeatedly target the same set of hosts. If unsolicited, identifying this behavior provides good insights on the malicious intent of scanners. In the case of innocuous scanners, publicly documenting scanning activities and giving right to opt out are common ethical practices. Our study shows that documented scanning IPs behave differently from the vast majority of scanners. Furthermore, only 39% of these entities follow online documentation best practices.
机译:扫描在Internet上无处不在。它可以帮助管理员对自己的网络进行故障排除,研究人员对互联网进行调查以及恶意行为者来评估目标网络的攻击面。随着用户需求的变化,野外扫描显示出非常多样化的特征。例如,从一个扫描IP到另一个扫描IP,覆盖范围,隐身性和探测速度都大不相同。在本文中,我们研究了15年的骨干网络流量,以了解小型网络中大规模扫描工具的使用,扫描模式和扫描IP(也称为扫描器)的集中度的演变。我们还提出了一种新方法,将扫描IP的空间和时间结构分为三个显示出不同意图的配置文件。特别是,我们发现33%的扫描仪反复针对同一组主机。如果不请自来,则识别此行为可以很好地了解扫描程序的恶意意图。对于无害的扫描仪,公开记录扫描活动并有权选择退出是常见的道德规范。我们的研究表明,记录的扫描IP的行为与绝大多数扫描仪不同。此外,这些实体中只有39%遵循在线文档最佳实践。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号