Internet Background Radiation Seminar in Distributed Computing - - PowerPoint PPT Presentation
Internet Background Radiation Seminar in Distributed Computing - - PowerPoint PPT Presentation
Internet Background Radiation Seminar in Distributed Computing Jeremia Br Internet Background Radiation? Network packets to unassigned addresses. Useless Traffic Internet Background Radiation, 2 Jeremia Br, 2. April 2014 Why would I
Internet Background Radiation?
Network packets to unassigned addresses. Useless Traffic
Internet Background Radiation, Jeremia Bär, 2. April 2014 2
Why would I care?
Internet Growth: 50% / annum IBR Growth: 100% / annum
Internet Background Radiation, Jeremia Bär, 2. April 2014 3
Radiation Sources
Computer Virus + Botnets Hacking / DDoS Hacking / DDoS Software Bugs + Misconfiguration
Internet Background Radiation, Jeremia Bär, 2. April 2014 4
Why would I care?
Internet Growth: 50% / annum IBR Growth: 100% / annum
Internet Background Radiation, Jeremia Bär, 2. April 2014 5
Analysis Techniques
- Packet Analysis
- Temporal Analysis
- Spatial Analysis
Internet Background Radiation, Jeremia Bär, 2. April 2014 6
Packet Analysis
– Headers Analysis – Payload Analysis
Temporal Analysis
allows – Application Identification – Application Popularity – Source OS allows
Analysis Techniques
Temporal Analysis
– Analysis of (src,dst) pairs – Cross-port analysis
Spatial Analysis
– Source Synchronization – Network Avoidance allows – Reveal Hidden Intention allows – Software Maturity –
Internet Background Radiation, Jeremia Bär, 2. April 2014 7
Packet Analysis
Approach
- Header Analysis
- Payload Analysis
Internet Background Radiation, Jeremia Bär, 2. April 2014 8
Results
- Application Identification
- Application Popularity
- Originating OS
Temporal Analysis
Approach
- Analyse (src, dst) pairs
- Cross-port analysis
Internet Background Radiation, Jeremia Bär, 2. April 2014 9
Results
- Identify Source Intention
Spatial Analysis
Approach
- Source Synchronization
- Network Avoidance
Internet Background Radiation, Jeremia Bär, 2. April 2014 10
Results
- Software Maturity
Spatial Analysis
Focus due to Software Bug
Internet Background Radiation, Jeremia Bär, 2. April 2014 11
Software Misconfiguration
Vendor bug in DSL Modem Traffic to 1.x.168.192 Focused Automated No Control Traffic to 35.206.63.212 Address Space Pollution No Control
Internet Background Radiation, Jeremia Bär, 2. April 2014 12
Summary
- Existance & Importance
- Packet, Temporal and Spatial Analysis
– Classification & Filtering – Study of Malware
Address Space Pollution
- Address Space Pollution
- Measurement of IBR
- Real-world Applications
Up Next
Internet Background Radiation, Jeremia Bär, 2. April 2014 13
Measuring IBR
Internet Background Radiation, Jeremia Bär, 2. April 2014 14
Measuring IBR
Darknets Black Holes
Internet Background Radiation, Jeremia Bär, 2. April 2014 15
Active Responder Complexity
Internet Background Radiation, Jeremia Bär, 2. April 2014 16
Real-world Applications
Christchurch, NZ. 22.Feb. 2011 Magnitude: 6.1 Tohoku, JP. 11. Mar. 2011 Magnitude: 9.0
Internet Background Radiation, Jeremia Bär, 2. April 2014 17
Infrastructure Impact
Internet Background Radiation, Jeremia Bär, 2. April 2014 18
Infrastructure Impact
Tohoku
Internet Background Radiation, Jeremia Bär, 2. April 2014 19
Infrastructure Impact
Christchurch
Internet Background Radiation, Jeremia Bär, 2. April 2014 20
Infrastructure Impact
Property Christchurch, NZ Tohoku, JP Magnitude 6.1 9.0 Magnitude 6.1 9.0 20km 304km 2 (6km) 3.59 (137km)
Internet Background Radiation, Jeremia Bär, 2. April 2014 21
Long-term Impact
Tohoku
Internet Background Radiation, Jeremia Bär, 2. April 2014 22
Long-term Impact
Christchurch
Internet Background Radiation, Jeremia Bär, 2. April 2014 23
Reliability
Tohoku
Internet Background Radiation, Jeremia Bär, 2. April 2014 24
Big Scope & Recovery
Internet Background Radiation, Jeremia Bär, 2. April 2014 25
Reliability
- Law enforcement
- ISP filtering
- Software Patches
- System Damage
- Accuracy of Geolocation
– Mobile Devices
Internet Background Radiation, Jeremia Bär, 2. April 2014 26
Summary
- Existance & Analysis
– Packets, Temporal, Spatial
- Measurement
Darknets, Active Responders – Darknets, Active Responders
- Tech Applications
– Classification, Malware, Address Space Pollution
- Geographic Colocation
– Communication Infrastructure Metric
Internet Background Radiation, Jeremia Bär, 2. April 2014 27
Thank You
- Characteristics of Internet Background Radiation.
Pang et al. In SIGCOMM 2004
- Internet Background Radiation Revisited.
Wustrow et al. In SIGCOMM 2010.
- Extracting Benefit from Harm: Using Malware Pollution to Analyze the
Impact of Political and Geophysical Events on the Internet. Dainotti et al. In SIGCOMM 2012.
Internet Background Radiation, Jeremia Bär, 2. April 2014 28