How to build socio-organizational information from remote IP addresses to enrich security analysis? - Inria - Institut national de recherche en sciences et technologies du numérique Accéder directement au contenu
Communication Dans Un Congrès Année : 2022

How to build socio-organizational information from remote IP addresses to enrich security analysis?

Résumé

There is a constant threat of having our computing systems under attack. Information regarding the origins of the traffic we receive can be valuable. Currently, the AS-number and the localization are the most commonly used IP-related information to characterize an attack. In this paper, we propose expanding knowledge about a remote IP's owner to improve defensive reaction effectiveness and obtain in-depth analyzes of attacker profiles. We introduce the enrichment with socioorganizational information (such as organization type, activity field, etc.) about the entities owning the IP in addition to infrastructural information. This integration is driven by combining RDAP and Wikidata. We demonstrate that this proposal is promising.
Fichier principal
Vignette du fichier
Moriot_lcn.pdf (258.73 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)

Dates et versions

hal-03901706 , version 1 (15-12-2022)

Identifiants

Citer

Camille Moriot, Francois Lesueur, Nicolas Stouls, Fabrice Valois. How to build socio-organizational information from remote IP addresses to enrich security analysis?. LCN 2022 - IEEE 47th Conference on Local Computer Networks, Sep 2022, Edmonton, Canada. pp.287-290, ⟨10.1109/LCN53696.2022.9843570⟩. ⟨hal-03901706⟩
43 Consultations
86 Téléchargements

Altmetric

Partager

Gmail Facebook X LinkedIn More