Mapping internet sensors with probe response attacks
John Bethencourt, Jason Franklin, Mary K. Vernon · 2005
Abstract Internet sensor networks, including honeypots and loganalysis centers such as the SANS Internet Storm Center, are used as a tool to detect malicious Internet traf-fic. For maximum effectiveness, such networks publish public reports without disclosing sensor locations, so thatthe Internet community can take steps to counteract the malicious traffic. Maintaining sensor anonymity is crit-ical because if the set of sensors is known, a malicious attacker could avoid the sensors entirely or could over-whelm the sensors with errant data.