Implications of Theoretic Derivations on Empirical Passive Measurements for Effective Cyber Threat Intelligence Generation
Morteza Safaei Pour, Elias Bou‐Harb · 2018
Cyber space continues to be threatened by various debilitating attacks. In this context, executing passive measurements by analyzing Internet-scale, one- way darknet traffic has proven to be an effective approach to shed the light on Internet-wide maliciousness. While typically such measurements are solely conducted from the empirical perspective on already deployed darknet IP spaces using off-the-shelf Intrusion Detection Systems (IDS), their multidimensional theoretical foundations, relations and implications continue to be obscured. In this paper, we take a first step towards comprehending the relation between attackers' behaviors, the width of the darknet vantage points, the probability of detection and the minimum detection time. We perform stochastic modeling, derivation, validation, inter-correlation and analysis of such parameters to provide numerous insightful inferences, such as the most effective IDS and the most suitable darknet IP space, given various attackers' activities in the presence of detection time/probability constraints. One of the outcomes suggests that the widely-deployed Bro IDS is ideal for inferring slow, stealthy probing activities by leveraging passive measurements. Further, the results do not recommend deploying the Snort IDS when the available darknet IP space is relatively small, which is a typical scenario when darknets are operated and employed on organizational sub-networks. We concur that the generated derivations and mathematical relations put forward a first-of-akind formal and an accurate characterization of darknet-centric notions, which possess significant implications on Internet and passive measurements. This is especially factual with the advent of evolving paradigms such as IPv6 deployments and the proliferation of highly-distributed, orchestrated, large-scale and stealthy probing botnets.