Network Telescope Data Analysis: IBR Monitoring
telescope/darknets/darkspace, 22 Mar 11
Nevil Brownlee
IBR Monitoring CAIDA, 2011 – p.1/17
Network Telescope Data Analysis: IBR Monitoring - - PowerPoint PPT Presentation
Network Telescope Data Analysis: IBR Monitoring telescope/darknets/darkspace, 22 Mar 11 Nevil Brownlee IBR Monitoring CAIDA, 2011 p.1/17 Background, Earlier Work Moore, Shannon et al, CAIDA/UCSD, 2000..2006 telescope gives a whole-world
Nevil Brownlee
IBR Monitoring CAIDA, 2011 – p.1/17
IBR Monitoring CAIDA, 2011 – p.2/17
IBR Monitoring CAIDA, 2011 – p.3/17
IBR Monitoring CAIDA, 2011 – p.4/17
IBR Monitoring CAIDA, 2011 – p.5/17
03 Apr 04 Apr 05 Apr 06 Apr 07 Apr 08 Apr 09 Apr 10 Apr 100 1000 10000 50 100 150 200 250 300 350 400 kS/h TCP port number Time (UTC)
03 Apr 04 Apr 05 Apr 06 Apr 07 Apr 08 Apr 09 Apr 10 Apr 100 1000 10000 50 100 150 200 250 300 350 400 450 500 kS/h TCP port number Time (UTC)
IBR Monitoring CAIDA, 2011 – p.6/17
20 40 60 80 100 120 140 16 Jan 30 Jan 13 Feb 27 Feb 13 Mar 27 Mar 10 Apr Counts: Thousands of Conficker P2P Sources, Jan - Apr 2010 (UTC) kS
20 40 60 80 100 16 Jan 30 Jan 13 Feb 27 Feb 13 Mar 27 Mar 10 Apr (b) Stacked-bar Time Series: Source % by Group, Jan - Apr 2010 (UTC) % Conficker P2P Other UDP TCP and UDP TCP Unclassified
IBR Monitoring CAIDA, 2011 – p.7/17
classifier = source address / prefix length simple system, no GUI (produces lists of prefix hierarchy)
classifier = n-grams (p, n) p = byte position in pkt, n = value of byte(s) Automatically determines n-gram used to split a group, find some bytes common to 50% of group picks arbitrary n-grams
IBR Monitoring CAIDA, 2011 – p.8/17
IBR Monitoring CAIDA, 2011 – p.9/17
IBR Monitoring CAIDA, 2011 – p.10/17
IBR Monitoring CAIDA, 2011 – p.11/17
IBR Monitoring CAIDA, 2011 – p.12/17
10 20 30 40 50 60 70 80 90 100 0.01 0.03 0.1 0.3 1 3 10 30 100 300 packet inter-arrival time (s) SAN, 1600 Tue 8 Mar 2011 (UTC): 09.10000-0-50, distributions 7 %
b0pc=99.85 mode=0.01 skew=-0.09 max=0.99
10 20 30 40 50 60 70 0.01 0.03 0.1 0.3 1 3 10 30 100 300 packet inter-arrival time (s) SAN, 1600 Tue 8 Mar 2011 (UTC): 09.10000-0-50, distributions 280 %
b0pc=33.33 mode=1.05 skew=0.00 max=1.05
5 10 15 20 25 30 35 0.01 0.03 0.1 0.3 1 3 10 30 100 300 packet inter-arrival time (s) SAN, 1600 Tue 8 Mar 2011 (UTC): 09.10000-0-50, distributions 168 %
b0pc=33.33 mode=500.49 skew=0.00 max=637.39
5 10 15 20 25 30 35 40 0.01 0.03 0.1 0.3 1 3 10 30 100 300 packet inter-arrival time (s) SAN, 1600 Tue 8 Mar 2011 (UTC): 09.10000-0-50, distributions 424 %
b0pc=40.00 mode=6.07 skew=40.00 max=179.11
IBR Monitoring CAIDA, 2011 – p.13/17
2 4 6 8 10 12 14 16 18 0.01 0.03 0.1 0.3 1 3 10 30 100 300 packet inter-arrival time (s) SAN, 1600 Tue 8 Mar 2011 (UTC): 09.10000-0-50, distributions 3 %
b0pc=0.16 mode=3.12 skew=-7.44 max=60.34
2 4 6 8 10 12 14 16 18 20 0.01 0.03 0.1 0.3 1 3 10 30 100 300 packet inter-arrival time (s) SAN, 1600 Tue 8 Mar 2011 (UTC): 09.10000-0-50, distributions 140 %
b0pc=0.62 mode=2.94 skew=3.50 max=68.09
2 4 6 8 10 12 0.01 0.03 0.1 0.3 1 3 10 30 100 300 packet inter-arrival time (s) SAN, 1600 Tue 8 Mar 2011 (UTC): 09.10000-0-50, distributions 326 %
b0pc=0.52 mode=3.12 skew=-6.64 max=76.84
5 10 15 20 25 0.01 0.03 0.1 0.3 1 3 10 30 100 300 packet inter-arrival time (s) SAN, 1600 Tue 8 Mar 2011 (UTC): 09.10000-0-50, distributions 188 %
b0pc=4.23 mode=3.12 skew=14.08 max=242.32
IBR Monitoring CAIDA, 2011 – p.14/17
2 4 6 8 10 12 14 16 18 20 0.01 0.03 0.1 0.3 1 3 10 30 100 300 packet inter-arrival time (s) SAN, 1600 Tue 8 Mar 2011 (UTC): 09.10000-0-50, distributions 2 %
b0pc=0.12 mode=3.32 skew=-39.12 max=110.44
2 4 6 8 10 12 14 0.01 0.03 0.1 0.3 1 3 10 30 100 300 packet inter-arrival time (s) SAN, 1600 Tue 8 Mar 2011 (UTC): 09.10000-0-50, distributions 38 %
b0pc=0.51 mode=3.12 skew=-47.18 max=21.59
0.5 1 1.5 2 2.5 3 3.5 4 4.5 0.01 0.03 0.1 0.3 1 3 10 30 100 300 packet inter-arrival time (s) SAN, 1600 Tue 8 Mar 2011 (UTC): 09.10000-0-50, distributions 17 %
b0pc=2.05 mode=3.12 skew=-79.76 max=22.94
2 4 6 8 10 12 14 16 0.01 0.03 0.1 0.3 1 3 10 30 100 300 packet inter-arrival time (s) SAN, 1600 Tue 8 Mar 2011 (UTC): 09.10000-0-50, distributions 47 %
b0pc=12.00 mode=2.94 skew=-44.00 max=9.84
IBR Monitoring CAIDA, 2011 – p.15/17
1 2 3 4 5 6 0.01 0.03 0.1 0.3 1 3 10 30 100 300 packet inter-arrival time (s) SAN, 1600 Tue 8 Mar 2011 (UTC): 09.10000-0-50, distributions 57 %
b0pc=0.64 mode=2.60 skew=29.87 max=32.97
0.5 1 1.5 2 2.5 3 3.5 4 4.5 0.01 0.03 0.1 0.3 1 3 10 30 100 300 packet inter-arrival time (s) SAN, 1600 Tue 8 Mar 2011 (UTC): 09.10000-0-50, distributions 145 %
b0pc=2.66 mode=0.51 skew=16.16 max=10.45
5 10 15 20 25 30 0.01 0.03 0.1 0.3 1 3 10 30 100 300 packet inter-arrival time (s) SAN, 1600 Tue 8 Mar 2011 (UTC): 09.10000-0-50, distributions 144 %
b0pc=0.11 mode=2.31 skew=46.22 max=29.21
5 10 15 20 25 30 35 40 45 50 0.01 0.03 0.1 0.3 1 3 10 30 100 300 packet inter-arrival time (s) SAN, 1600 Tue 8 Mar 2011 (UTC): 09.10000-0-50, distributions 244 %
b0pc=0.11 mode=3.12 skew=49.89 max=8.21
IBR Monitoring CAIDA, 2011 – p.16/17
IBR Monitoring CAIDA, 2011 – p.17/17