Verification of the Effectiveness to Monitor Darknet across Multiple Organizations

Katsuya Nishijima, Takao Kondo, Tatsumi Hosokawa, Tomohiro Shigemoto, Nobutaka Kawaguchi, Hiroyuki Hasegawa, Hideyuki Honda, Yasuhito Suzuki, Tadashi Kaji, Osamu Nakamura

Research output: Chapter in Book/Report/Conference proceedingConference contribution

Abstract

Researchers and network operators regularly monitor unused Internet address space called the darknet to understand malicious activities on the Internet such as malware infections, DDoS, and scanning to find vulnerable systems. The purpose of this study is to demonstrate the effectiveness of darknet monitoring across multiple organizations by conducting a detailed similarity analysis. In this paper, we analyze darknet data observed in two organizations in different industries and the first octet subnet range. We compared the results of the similarity analysis between intra-organization and inter-organization calculations by dividing the address space into multiple blocks so that one organization conducts similarity analysis in an intra-organization manner. The results show that the similarity of the source hosts is lower in the inter-organization calculation than in the intra-organization calculation. In addition, we monitor more source hosts in inter-organization. Moreover, this work also reports that the results differ depending on the destination ports/protocols. From the results obtained, we clarified the effectiveness of distributing the monitoring points of the darknet across multiple organizations.

Original languageEnglish
Title of host publicationProceedings - 2021 9th International Symposium on Computing and Networking Workshops, CANDARW 2021
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages346-351
Number of pages6
ISBN (Electronic)9781665428354
DOIs
Publication statusPublished - 2021
Event9th International Symposium on Computing and Networking Workshops, CANDARW 2021 - Virtual, Online, Japan
Duration: 2021 Nov 232021 Nov 26

Publication series

NameProceedings - 2021 9th International Symposium on Computing and Networking Workshops, CANDARW 2021

Conference

Conference9th International Symposium on Computing and Networking Workshops, CANDARW 2021
Country/TerritoryJapan
CityVirtual, Online
Period21/11/2321/11/26

Keywords

  • darknet
  • darknet placement
  • similarity analysis

ASJC Scopus subject areas

  • Artificial Intelligence
  • Computer Networks and Communications
  • Information Systems
  • Software

Fingerprint

Dive into the research topics of 'Verification of the Effectiveness to Monitor Darknet across Multiple Organizations'. Together they form a unique fingerprint.

Cite this