Identifying dynamic IP address blocks serendipitously through background scanning traffic

Yu Jin, Esam Sharafuddin, Zhi Li Zhang · 2007

Today’s Internet contains a large portion of “dynamic ” IP ad-dresses, which are assigned to clients upon request. A signif-icant amount of malicious activities have been reported from dynamic IP space, such as spamming, botnets, etc.. Accurate identification of dynamic IP addresses will help build black-lists of suspicious hosts with more confidence, and help track the sources of different types of anomalous activities. In this paper, we contrast traffic activity patterns between static and dynamic IP addresses in a large campus network, as well as their activity patterns when countering outside scanning traffic. Based on the distinct characteristics observed, we propose a scanning-based technique for identifying dynamic IP addresses in blocks. We conduct an experiment using a month-long data collected from our campus network, and instead of scanning our own network, we utilize identified outside scanning traffic. The experiment results demonstrate a high classification rate with low false positive rate. As an on-going work, we also introduce our design of an online classifier that identifies dynamic IP addresses in any network in real-time. 1.

Read the paper · More papers on PaperTik