A New Service for Increasing the Effectiveness of Network Address Blacklists
نویسندگان
چکیده
We recently established a new experimental Internet service for creating customized source address blacklists for DShield.org contributors. This new service utilizes a radically different approach to blacklist formulation that we refer to as Highly Predictive Blacklists (HPB). A highly predictive blacklist is a list of malicious Internet addresses that is formulated through an analysis of the roughly 30 million firewall log entries that are contributed to the DShield repository each day from across the Internet. The HPB service employs a link analysis algorithm similar to the Google PageRank scheme to crosscompare contributors in search of overlaps among the attackers they report. The attacker addresses included within an HPB are selected by favoring the inclusion of those addresses that have been encountered by contributors who share degrees of overlap with the target HPB owner. Our experiments show that highly predictive blacklist entries consistently yield filters that are exercised at higher rates than those from conventional blacklist methods. In addition, this increase in blacklist filter “hit rates” can last multiple days into the future. In this paper, we provide an overview of our algorithm and present our usage experiences. We discuss the envisioned benefits that we believe HPBs can provide toward reducing unwanted communications for those networks that utilize this service.
منابع مشابه
A New Mathematical Model To Optimize A Green Gas Network: A Case Study
Global warming created by large scale emissions of Greenhouse Gases (GHG) are a worldwide concern. Due to this, the issue of green gas network has required more attention in the last decades. Here, we address the GHG-based problem that arises in a gas network where gas flow is transferred from the Town Board Station (TBS) to consumers by pipeline systems. Given this environment, an optimization...
متن کاملThe Use of Data Envelopment Analysis in the Design of Internet Networks to Ensure the Quality of Service
Choosing a superior Internet network by users or providing a desirable Internet network by ISPs is always one of the important decision issues in this area. Choosing a unique optimal network from among the best networks is still a big challenge. The purpose of this paper is to use the data envelopment analysis (DEA) decision-making technique to evaluate the existing Internet networks in order t...
متن کاملA method to increasing the Quality of Service (QoS) in Wireless body area networks by providing a MAC layer Protocol based of Internet of Things
With the development of technology, the use of wireless telecommunication networks for the various affairs is essential. These networks are one of the safest and most widely used networks, for instance, in medical care and remote patient monitoring. What matters is the quality of service in these networks. The purpose of this paper is to increase packet transduction in a wireless body area netw...
متن کاملOptimal Coding Subgraph Selection under Survivability Constraint
Nowadays communication networks have become an essential and inevitable part of human life. Hence, there is an ever-increasing need for expanding bandwidth, decreasing delay and data transfer costs. These needs necessitate the efficient use of network facilities. Network coding is a new paradigm that allows the intermediate nodes in a network to create new packets by combining the packets recei...
متن کاملBotOnus: an online unsupervised method for Botnet detection
Botnets are recognized as one of the most dangerous threats to the Internet infrastructure. They are used for malicious activities such as launching distributed denial of service attacks, sending spam, and leaking personal information. Existing botnet detection methods produce a number of good ideas, but they are far from complete yet, since most of them cannot detect botnets in an early stage ...
متن کامل