Advanced Geolocation of IP Addresses
نویسندگان
چکیده
Tracing and locating the geographical location of users (Geolocation) is used extensively in today’s Internet. Whenever we, e.g., request a page from google we are unless there was a specific configuration made automatically forwarded to the page with the relevant language and amongst others, dependent on our location identified, specific commercials are presented. Especially within the area of network security, Geolocation has a significant impact. Because of the way the Internet works, attacks can be executed from almost everywhere. Therefore, for an attribution, knowledge of the origination of an attack and thus Geolocation is mandatory in order to be able to trace back an attacker. In addition, Geolocation can also be used very successfully to increase the security of a network during operation (i.e. before an intrusion actually has taken place). Similar to greylisting in emails, Geolocation allows to (i) correlate attacks detected with new connections and (ii) as a consequence to classify traffic a priori as more suspicious (thus particularly allowing to inspect this traffic in more detail). Although numerous techniques for Geolocation exist, each strategy is subject to certain restrictions. Following the ideas of Endo et al., this publication tries to overcome these shortcomings with a combined solution of different methods to allow improved and optimized Geolocation. Thus, we present our architecture for improved Geolocation, by designing a new algorithm, which combines several Geolocation techniques to increase the accuracy. Keywords—IP geolocation, prosecution of computer fraud, attack attribution, target-analysis
منابع مشابه
A Study of Geolocation Databases
The geographical location of Internet IP addresses has an importance both for academic research and commercial applications. Thus, both commercial and academic databases and tools are available for mapping IP addresses to geographic locations. Evaluating the accuracy of these mapping services is complex since obtaining diverse large scale ground truth is very hard. In this work we evaluate mapp...
متن کاملMining the Web for IP Address Geolocations
In this paper, we observe that many Web pages contain geolocation information (address, zipcode, and telephone area code) and many of these geolocation items are directly related to the locations of the IP addresses that host the Web pages. We then design Structon, a system that mines Web pages for IP address geolocations. In Structon, we first extract geolocation information from every crawled...
متن کاملComparing the Accuracy of IPv4 and IPv6 Geolocation Databases
IPv4 geolocation has been around for some time, but IPv6 geolocation is relatively new. This raises the question as to how the accuracy of IPv6 geolocation compares to the accuracy of IPv4 geolocation. Since IPv6 geolocation is a reasonably new topic, litte research has been done on its accuracy. In this study the accuracy is measured using a ground truth consisting of very precise locations of...
متن کاملGeolocating IP Addresses in Cellular Data Networks
Smartphones connected to cellular networks are increasingly being used to access Internet-based services. Using data collected from smartphones running a popular location-based application, we examine IP address allocation in cellular data networks, with emphasis on understanding the applicability of IP-based geolocation techniques. Our dataset has GPS-based location data for approximately 29,0...
متن کاملMapping Web Pages by Internet Protocol (IP) addresses: Analyzing Spatial and Temporal Characteristics of Web Search Engine Results
Internet Protocol (IP) addresses are frequently used as a method of locating web users by researchers in several different fields. However, there are competing reports concerning the accuracy of those locations, and little research has been done in manually comparing the IP geolocation databases and web page geographic information. This paper categorized web page from the Yahoo search engine in...
متن کامل