| 摘要: |
| 因特网背景辐射(Internet background radiation,简称IBR)是一种无功流量,已被广泛用于网络安全和管理等领域的研究中.传统的IBR获取方式——暗网系统存在较难满足的布置条件和易被避开的弊端,因此,提出一种从运行网络中获取IBR的算法.该算法基于灰空间、单向流和行为学习这3个概念,能够较准确地获取运行网络的所有IBR流量.一方面,它同时获取了不活跃地址和活跃地址的IBR流量,比现有的基于不活跃地址的算法漏判率低;另一方面,该算法在单向流基础上增加了基于源点的行为学习.与现有的基于单向流的算法相比,虽然查全率有少许降低,但查准率从约93%提升至99%以上.通过将算法运用到一个拥有约128万个IP地址的运行网络,从多个角度对该运行网络中的IBR进行了分析.结果显示,近两年,样本数据中70%以上的入流为IBR流,这一现象应引起相关研究的注意.最后,通过几个安全事件案例说明了运行网络IBR流量在网络安全和管理等领域中的重要作用. |
| 关键词: 因特网背景辐射 灰空间 单向流 IBR分类 网络威胁 |
| DOI:10.13328/j.cnki.jos.004516 |
| 分类号: |
| 基金项目:国家重点基础研究发展计划(973)(2009CB320505); 国家科技攻关计划(2008BAH37B04) |
|
| Extracting and Analyzing Internet Background Radiation in Live Networks |
|
MIAO Li-Hua1,2, DING Wei1,2, YANG Wang1,2
|
|
1.School of Computer Science and Engineering, Southeast University, Nanjing 211189, China;2.Key Laboratory of Computer Network Technology in Jiangsu, Nanjing 211189, China
|
| Abstract: |
| Internet background radiation (IBR) is a type of unproductive traffic which has been used for years in the network security and management fields. Traditionally, IBR can be obtained by darknets. Nevertheless, the deployment of darknets typically requires large dark address blocks which are hard to acquire and also potentially detectable and avoidable. To address the issue, this article proposes an algorithm to extract IBR from raw traffic in live networks. The algorithm is based on the notions of grey spaces, one-way flows and behavior learning and has a better performance than previous work. On one hand, the algorithm obtains IBR destined to both inactive addresses and active addresses, resulting a lower missing rate compared with algorithms based on inactive addresses. On the other hand, the algorithm employs a behavior learning mechanism. Although the metric "recall" decreases slightly, "precision" increases from about 93% to above 99% in contrast to algorithms based on one-way flows. After applying the algorithm to a live network consisting of about 1.28 million IP addresses, the study analyzes the extracted IBR from several aspects. Results show that more than 70% of the inbound flows are IBR flows in the past two years' data samples and this should draw enough attention from related research. Finally, several cases suggest the important role the live networks' IBR traffic plays in the network security and management fields. |
| Key words: Internet background radiation grey space one-way flow IBR classification Internet threat |