Abstract
number of security-related research topics are based on the monitoring of dark IP address space. Unfortunately there is large administrative overhead associated with the dynamic assignment of a specific subnet for monitoring purposes, such as the deployment of a honeypot farm or a distributed intrusion detection system. In this paper, we propose a system that enables the dynamic allocation of an unadvertised IP address subnet for use by a monitoring sensor. The system dynamically selects network subnets that have been allocated to the organization but are not being advertised, advertises them, and subsequently forwards all received traffic destined to the selected subnet to a monitoring sensor.
This work was supported in part by the project SysSec funded in part by the European Commission, under Grant Agreement Number 257007.
Access this chapter
Tax calculation will be finalised at checkout
Purchases are for personal use only
Preview
Unable to display preview. Download preview PDF.
Similar content being viewed by others
References
Deri, L.: High-speed dynamic packet filtering. Journal of Network and Systems Management 15(3), 401–415 (2007)
Jiang, X., Xu, D.: Collapsar: A VM-Based Architecture for Network Attack Detention Center. In: Proceedings of the 13th USENIX Security Sumposium (2004)
Di Pietro, A., Huici, F., Costantini, D., Niccolini, S.: Decon: Decentralized coordination for large-scale flow monitoring. In: IEEE Conference on Computer Communications, INFOCOM (2010)
Anagnostakis, K., Antonatos, S., Markatos, E.P.: Honey@home: A new approach to large-scale threat monitoring. In: The Proceedings of the 5th ACM Workshop on Recurring Malcode, WORM (2007)
Trimintzios, P., Polychronakis, M., Papadogiannakis, A., Foukarakis, M., Markatos, E., Øslebø, A.: DiMAPI: An application programming interface for distributed network monitoring. In: Proceedings of the 10th IEEE/IFIP Network Operations and Management Symposium, NOMS (2006)
Wu, Z., Xie, M., Wang, H.: Swift: a fast dynamic packet filter. In: Proceedings of the 5th USENIX Symposium on Networked Systems Design and Implementation, NSDI 2008 (2008)
Author information
Authors and Affiliations
Editor information
Editors and Affiliations
Rights and permissions
Copyright information
© 2011 Springer-Verlag Berlin Heidelberg
About this paper
Cite this paper
Polakis, I., Kontaxis, G., Ioannidis, S., Markatos, E.P. (2011). Dynamic Monitoring of Dark IP Address Space (Poster). In: Domingo-Pascual, J., Shavitt, Y., Uhlig, S. (eds) Traffic Monitoring and Analysis. TMA 2011. Lecture Notes in Computer Science, vol 6613. Springer, Berlin, Heidelberg. https://doi.org/10.1007/978-3-642-20305-3_20
Download citation
DOI: https://doi.org/10.1007/978-3-642-20305-3_20
Publisher Name: Springer, Berlin, Heidelberg
Print ISBN: 978-3-642-20304-6
Online ISBN: 978-3-642-20305-3
eBook Packages: Computer ScienceComputer Science (R0)