A System for Characterising Internet Background Radiation
David Yates · 2014
Internet traffic sent to addresses where no device is set up to receive it is termed internet background radiation (IBR), and has been collected and studied by numerous parties since the early 2000s. This data has been shown to provide valuable insights into malicious activity on networks, and as all IBR is by nature unsolicited, there is no need to filter out legitimate traffic from the datasets before using it performing botnet and worm-related analysis. The primary aim of this project was to develop a set of tools for exploring and characterising this data, on an historic basis. The datasets used for this purpose were collected from five network telescopes operating at Rhodes University from late 2013 to early 2014. A secondary aim is to use this set of tools to perform analysis on the data and discover significant trends that can then feed into further development of the system. ACM Computing Classification System Classification Thesis classification under the ACM Computing Classification System (2012 version, valid through 2014) [16]: D.7.7 [Network services]: Network monitoring D.7.6 [Network services]: Network management General-Terms: Metrics, Experimentation