Luca Gioacchini
Automatic Detection of Coordinated Events in Darknet Traffic.
Rel. Luca Vassio, Francesca Soro, Idilio Drago. Politecnico di Torino, Master of science program in Ict For Smart Societies, 2021
|
Preview |
PDF (Tesi_di_laurea)
- Thesis
Licence: Creative Commons Attribution Non-commercial No Derivatives. Download (2MB) | Preview |
Abstract
Darknets are network monitoring tools composed by sets of IP addresses announced in routing protocols, but without hosting any services. They constantly listen to incoming traffic and record it. The received packets are thus unsolicited and represent a privileged source of information for network security. Indeed, the lack of any production traffic in darknet makes it easier to detect possible threats like internal scans, brute-force attempts against services, etc. Detecting and evaluating coordinated events is an important step to fully exploit the darknet monitoring potential. Indeed it could reduce the amount of data to be evaluated by security analysts and provide a richer picture about ongoing attacks on the Internet.
Given the huge amount of source IPs constantly targeting darknets, a manual analysis on the received traffic is impractical
Relators
Publication type
URI
![]() |
Modify record (reserved for operators) |
