Logo del repository
  1. Home
 
Opzioni

Can Blocklists Explain Darknet Traffic?

Ravalico, Damiano
•
Valentim, Rodolfo
•
Trevisan, Martino
•
Drago, Idilio
2024
  • conference object

Abstract
Darknets are IP addresses that function as passive probes, recording all received packets without hosting services. The traffic they capture, being unsolicited, makes darknets akin to “network telescopes”. Traces collected on darknets aggregate multiple events useful for cybersecurity, like network scans and exploit attempts. Yet, the mix of heterogeneous events observed from darknets poses significant challenges to those who must understand darknet traffic. Here we face the question of whether new darknet deployments provide novel and useful information when compared to public blocklists. Multiple Cyber Threat Intelligence (CTI) sources publish lists of IP addresses that perform malicious activities, from simple automated scans to SPAM and phishing campaigns. They represent a valuable resource for network administrators, helping to block cyberattacks. Built with a combination of multiple sensors — including darknets and honeypots — these lists could explain the traffic seen on other darknets, thus simplifying the search for relevant events in independent darknet deployments. We thus investigate to what extent open blocklists explain darknet traffic. By crawling hundreds of CTI sources providing blocklists, we first notice how these lists are often incomplete or slowly updated. Traffic seen in our darknet deployment is hardly explained by the blocklists, even when considering only the most prominent scan attempts, and ignoring events such as backscattering. Our preliminary results suggest that blocklists can be of great use for seeding the explanation of darknet traffic, by giving context for the activity of a few IP addresses. Yet, more addresses with similar behaviour are observed in the darknet and could be used to enrich and complement the blocklists.
DOI
10.23919/tma62044.2024.10558914
WOS
WOS:001258591000002
Archivio
https://hdl.handle.net/11368/3079158
info:eu-repo/semantics/altIdentifier/scopus/2-s2.0-85197893501
https://ieeexplore.ieee.org/abstract/document/10558914
Diritti
closed access
license:copyright editore
license uri:iris.pri02
FVG url
https://arts.units.it/request-item?handle=11368/3079158
Soggetti
  • Darknet

  • Blocklist

  • cybersecurity

google-scholar
Get Involved!
  • Source Code
  • Documentation
  • Slack Channel
Make it your own

DSpace-CRIS can be extensively configured to meet your needs. Decide which information need to be collected and available with fine-grained security. Start updating the theme to match your nstitution's web identity.

Need professional help?

The original creators of DSpace-CRIS at 4Science can take your project to the next level, get in touch!

Realizzato con Software DSpace-CRIS - Estensione mantenuta e ottimizzata da 4Science

  • Impostazioni dei cookie
  • Informativa sulla privacy
  • Accordo con l'utente finale
  • Invia il tuo Feedback