Comprehensive Classification of Internet Background Noise

Maxim O. Zolotykh · 2020

Internet background noise (IBN, also known as Internet background radiation) is unsolicited network packets. For example, packets addressed to non-existing host. There are several reasons for background noises: untargeted scanning of global network in search of vulnerable hosts, network devices misconfiguration, backscatters of DDoS attacks with IP-spoofing technology, traces of worms propagation etc. We study background noises with dark collector - it is the trap that records all incoming packets and does not respond to them or do any other activity (term constructed in opposite to honeypot). In this research, we captured about ten millions packets of background noise. All captured packets was divided into groups according to character combination of flags and parameters in network, transport and application headers. For each group of packets the reason of appearing in the background noise was suggested and statistical characteristic was given. We suppose that different kinds of noises should be study separately. It will allow to study global networks threats trends by changing frequency of appearing packets from such groups. Based on the given classification, what may be developed are the dashboards for global network monitoring as well as the triggers of new kinds of attacks.

Read the paper · More papers on PaperTik