Survey on Identification of Malicious Activities by Monitoring Darknet Access
Preeti S. Joshi, H A Dinesha · 2020 Third International Conference on Smart Systems and Inventive Technology (ICSSIT) · 2020
The evolutionary types of attacks generated by attacker makes it difficult to identify them. Novel tools and techniques are required to detect, analyze, and generate reports for threat intelligence. Sensors placed in unused or unassigned IP addresses and used to monitor traffic passively are called Darknets or network telescopes. Attempt to access darknet addresses can be classified as malicious activity. Monitoring traffic reaching darknet addresses can generate cyber intelligence indicating activities going on the Internet. They are looked as a means for early detection of cyber-attacks. This paper presents an overview of recent work done in the field of darknet monitoring. This paper analyzes the limitations and challenges related to identification of malicious traffic by passive monitoring of traffic. The suggestions are compiled for improvement.