Gray's anatomy: dissecting scanning activities using IP gray space analysis

  • Authors:
  • Yu Jin;György Simon;Kuai Xu;Zhi-Li Zhang;Vipin Kumar

  • Affiliations:
  • Department of Computer Science, University of Minnesota;Department of Computer Science, University of Minnesota;Department of Computer Science, University of Minnesota;Department of Computer Science, University of Minnesota;Department of Computer Science, University of Minnesota

  • Venue:
  • SYSML'07 Proceedings of the 2nd USENIX workshop on Tackling computer systems problems with machine learning techniques
  • Year:
  • 2007

Quantified Score

Hi-index 0.00

Visualization

Abstract

In this paper, we study the scanning activities towards a large campus network using a month-long netflow traffic trace. Based on the novel notion of "gray" IP space (namely, collection of IP addresses within our campus network that are not assigned to any "active" host during a certain period of time), we identify and extract potential outside scanners and their associated activities. We then apply data mining and machine learning techniques to analyze the scanning patterns of these scanners and classify them into a few groups (e.g., focused hitters, random address scanners, and blockwise scanners). The goal is to infer the scanning strategies of the scanners so as to provide some assessment of the potential harmfulness of these scanning activities - for example, whether the observed scanning activities are simply part of background radiation of global random scanning or more focused scanning targeted at our campus network. This is an on-going work; we report some preliminary, yet promising results obtained so far.