Evaluating Bad Hosts Using Adaptive Blacklist Filter

Karel Hynek, Tomáš Čejka, Martin Žádník, Hana Kubátová · 2020

Publicly available blacklists are popular tools to capture and spread information about misbehaving entities on the Internet. In some cases, their straight-forward utilization leads to many false positives. In this work, we propose a system that combines blacklists with network flow data while introducing automated evaluation techniques to avoid reporting unreliable alerts. The core of the system is formed by an Adaptive Filter together with an Evaluator module. The assessment of the system was performed on data obtained from a national backbone network. The results show the contribution of such a system to the reduction of unreliable alerts.

Read the paper · More papers on PaperTik