Modeling of IP scanning activities with Hidden Markov Models: Darknet case study - Inria - Institut national de recherche en sciences et technologies du numérique Access content directly
Conference Papers Year : 2016

Modeling of IP scanning activities with Hidden Markov Models: Darknet case study

Abstract

We propose a methodology based on Hidden Markov Models (HMMs) to model scanning activities monitored by a darknet. The HMMs of scanning activities are built on the basis of the number of scanned IP addresses within a time window and fitted using mixtures of Poisson distributions. Our methodology is applied on real data traces collected from a darknet and generated by two large scale scanners, ZMap and Shodan. We demonstrated that the built models are able to characterize their scanning activities.
Fichier principal
Vignette du fichier
NTMS2016.pdf (2.54 Mo) Télécharger le fichier
Origin : Files produced by the author(s)
Loading...

Dates and versions

hal-01404127 , version 1 (28-11-2016)

Identifiers

  • HAL Id : hal-01404127 , version 1

Cite

Giulia de Santis, Abdelkader Lahmadi, Jerome Francois, Olivier Festor. Modeling of IP scanning activities with Hidden Markov Models: Darknet case study. 8th IFIP International Conference on New Technologies, Mobility and Security, Nov 2016, Larnaca, Cyprus. ⟨hal-01404127⟩
333 View
557 Download

Share

Gmail Facebook X LinkedIn More