Are darknets all the same? On darknet visibility for security monitoring

Francesca Soro, Idilio Drago, Martino Trevisan, Marco Mellia, Joao Ceron, Jose J. Santanna

Research output: Chapter in Book/Report/Conference proceedingConference contributionAcademicpeer-review

18 Citations (Scopus)
26 Downloads (Pure)

Abstract

Darknets are sets of IP addresses that are advertised but do not host any client or server. By passively recording the incoming packets, they assist network monitoring activities. Since packets they receive are unsolicited by definition, darknets help to spot misconfigurations as well as important security events, such as the appearance and spread of botnets, DDoS attacks using spoofed IP address, etc. A number of organizations worldwide deploys darknets, ranging from a few dozens of IP addresses to large/8 networks. We here investigate how similar is the visibility of different darknets. By relying on traffic from three darknets deployed in different contintents, we evaluate their exposure in terms of observed events given their allocated IP addresses. The latter is particularly relevant considering the shortage of IPv4 addresses on the Internet. Our results suggest that some well-known facts about darknet visibility seem invariant across deployments, such as the most commonly contacted ports. However, size and location matter. We find significant differences in the observed traffic from darknets deployed in different IP ranges as well as according to the size of the IP range allocated for the monitoring.

Original languageEnglish
Title of host publication25th IEEE International Symposium on Local and Metropolitan Area Networks, LANMAN 2019
PublisherIEEE
ISBN (Electronic)9781728114347
DOIs
Publication statusPublished - 26 Sept 2019
Event25th IEEE International Symposium on Local and Metropolitan Area Networks, LANMAN 2019 - Paris, France
Duration: 1 Jul 20193 Jul 2019
Conference number: 25

Publication series

NameIEEE Workshop on Local and Metropolitan Area Networks
Volume2019-July
ISSN (Print)1944-0367
ISSN (Electronic)1944-0375

Conference

Conference25th IEEE International Symposium on Local and Metropolitan Area Networks, LANMAN 2019
Abbreviated titleLANMAN 2019
Country/TerritoryFrance
CityParis
Period1/07/193/07/19

Keywords

  • Darknets
  • Darkspaces
  • Network telescopes
  • Sinks

Fingerprint

Dive into the research topics of 'Are darknets all the same? On darknet visibility for security monitoring'. Together they form a unique fingerprint.

Cite this