Monitoring bad traffic with darknets

Simon Woodhead · Network Security · 2012

A common form of ‘darknet’ used by security researchers and analysts is a block of unused address space on a network. As the address-space is unused, and ideally has never been used, any traffic destined for this address-space is in some way improper. By monitoring traffic hitting the darknet we can build up a picture of aberrant traffic without the false positives that plague other technologies, particularly at scale.

Read the paper · More papers on PaperTik