Internet Background Radiation Seminar in Distributed Computing Jeremia Bär
Internet Background Radiation? Network packets to unassigned addresses. Useless Traffic Internet Background Radiation, 2 Jeremia Bär, 2. April 2014
Why would I care? Internet Growth: 50% / annum IBR Growth: 100% / annum Internet Background Radiation, 3 Jeremia Bär, 2. April 2014
Radiation Sources Computer Virus + Botnets Hacking / DDoS Hacking / DDoS Software Bugs + Misconfiguration Internet Background Radiation, 4 Jeremia Bär, 2. April 2014
Why would I care? Internet Growth: 50% / annum IBR Growth: 100% / annum Internet Background Radiation, 5 Jeremia Bär, 2. April 2014
Analysis Techniques • Packet Analysis • Temporal Analysis • Spatial Analysis Internet Background Radiation, 6 Jeremia Bär, 2. April 2014
Analysis Techniques Packet Analysis allows – Headers Analysis – Application Identification – Payload Analysis – Application Popularity – Source OS Temporal Analysis Temporal Analysis allows allows – Analysis of (src,dst) pairs – Reveal Hidden Intention – Cross-port analysis Spatial Analysis allows – Source Synchronization – Software Maturity – Network Avoidance – Internet Background Radiation, 7 Jeremia Bär, 2. April 2014
Packet Analysis Approach • Header Analysis • Payload Analysis Results • Application Identification • Application Popularity • Originating OS Internet Background Radiation, 8 Jeremia Bär, 2. April 2014
Temporal Analysis Approach • Analyse (src, dst) pairs • Cross-port analysis Results • Identify Source Intention Internet Background Radiation, 9 Jeremia Bär, 2. April 2014
Spatial Analysis Approach • Source Synchronization • Network Avoidance Results • Software Maturity Internet Background Radiation, 10 Jeremia Bär, 2. April 2014
Spatial Analysis Focus due to Software Bug Internet Background Radiation, 11 Jeremia Bär, 2. April 2014
Software Misconfiguration Vendor bug in DSL Modem Focused Traffic to 1.x.168.192 Automated No Control No Control Traffic to 35.206.63.212 Address Space Pollution Internet Background Radiation, 12 Jeremia Bär, 2. April 2014
Summary • Existance & Importance • Packet, Temporal and Spatial Analysis – Classification & Filtering – Study of Malware • Address Space Pollution Address Space Pollution Up Next • Measurement of IBR • Real-world Applications Internet Background Radiation, 13 Jeremia Bär, 2. April 2014
Measuring IBR Internet Background Radiation, 14 Jeremia Bär, 2. April 2014
Measuring IBR Darknets Black Holes Internet Background Radiation, 15 Jeremia Bär, 2. April 2014
Active Responder Complexity Internet Background Radiation, 16 Jeremia Bär, 2. April 2014
Real-world Applications Christchurch, NZ. 22.Feb. 2011 Tohoku, JP. 11. Mar. 2011 Magnitude: 6.1 Magnitude: 9.0 Internet Background Radiation, 17 Jeremia Bär, 2. April 2014
Infrastructure Impact Internet Background Radiation, 18 Jeremia Bär, 2. April 2014
Infrastructure Impact Tohoku Internet Background Radiation, 19 Jeremia Bär, 2. April 2014
Infrastructure Impact Christchurch Internet Background Radiation, 20 Jeremia Bär, 2. April 2014
Infrastructure Impact Property Christchurch, NZ Tohoku, JP Magnitude Magnitude 6.1 6.1 9.0 9.0 20km 304km 2 (6km) 3.59 (137km) Internet Background Radiation, 21 Jeremia Bär, 2. April 2014
Long-term Impact Tohoku Internet Background Radiation, 22 Jeremia Bär, 2. April 2014
Long-term Impact Christchurch Internet Background Radiation, 23 Jeremia Bär, 2. April 2014
Reliability Tohoku Internet Background Radiation, 24 Jeremia Bär, 2. April 2014
Big Scope & Recovery Internet Background Radiation, 25 Jeremia Bär, 2. April 2014
Reliability • Law enforcement • ISP filtering • Software Patches • System Damage • Accuracy of Geolocation – Mobile Devices Internet Background Radiation, 26 Jeremia Bär, 2. April 2014
Summary • Existance & Analysis – Packets, Temporal, Spatial • Measurement – Darknets, Active Responders Darknets, Active Responders • Tech Applications – Classification, Malware, Address Space Pollution • Geographic Colocation – Communication Infrastructure Metric Internet Background Radiation, 27 Jeremia Bär, 2. April 2014
Thank You Characteristics of Internet Background Radiation. • Pang et al. In SIGCOMM 2004 Internet Background Radiation Revisited. • Wustrow et al. In SIGCOMM 2010. Extracting Benefit from Harm: Using Malware Pollution to Analyze the • Impact of Political and Geophysical Events on the Internet. Dainotti et al. In SIGCOMM 2012. Internet Background Radiation, 28 Jeremia Bär, 2. April 2014
Recommend
More recommend