ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Network management Toolkit

How much is junk traffic costing you?

Jonathan Yarden

Published: 08 Dec 2005 08:25 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A few weeks ago, a coworker asked me a simple question: How much of the Internet traffic coming into our network was "junk", and how much was this unwanted traffic costing us? Before delving too deeply into his request, I asked him to define the term junk. His classification included suspected port scans, attempts to exploit known weaknesses in applications, and attempted connections to TCP and UDP services on hosts that didn't provide those services.

He asked me to generate a list of offending networks that were the source of junk traffic in the past 30 days. At first, it seemed almost too easy. However, after only a few hours of work, I realised I had underestimated how involved a task it really was.

Finally, after a few days of work, I managed to produce a rather comprehensive list of IP addresses that were sources of junk data. I used a variety of means to gather this data, including NetFlow data, system log files, Snort, and a darknet.

In all, approximately 2.8 million distinct IP addresses from all over the world were responsible for junk traffic on my organisation's network in the past month. And keep in mind that this doesn't include delivered junk email.

Next, I needed to somehow organise these different IP addresses into networks and identify where all the junk was coming from. And this isn't exactly a simple task when you're dealing with so much data.

Since my first step was to aggregate the data, I decided to get a list of the delegated Internet networks from the FTP site of the American Registry for Internet Numbers (ARIN). However, ARIN uses the Border Gateway Protocol (BGP), and the smallest network I could focus on was a /24 or Class C network because of how BGP works.

An hour or two of coding and testing later, and I had an aggregation tool that ordered the junk-sending IP addresses into worldwide networks. Of the approximate 250,000 network paths obtained from ARIN and the 2.8 million junk-sending IP addresses, I had a list of roughly 40,000 networks that were responsible for junk traffic on my organisation's network in the past month.

Next, I used another program to separate the collected data by country into ARIN (North America, the Caribbean, and Southern Africa), APNIC (Asia and the Pacific region), LACNIC (Latin America and...

Next

Previous

1 2


  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with HP

Did you find this article useful?
114 out of 195 people found this useful



Company/Topic Alerts

Create a new alert from the list below:






Related Jobs

Are you a desktop engineer looking to develop your skills? SE.Ldn 25k

It is important to be able to build and support networks and multi task prioritising the tasks at hand. Support Engineer/ MCP/ AD/ Exchange/ XP/ ...

Backup Administrator - Windows, Veritas, Legato, Netbackup, Omniback - West London

You must be able to prioritise and multi-task, as well as be an active team player, who is willing to go the 'extra mile' to provide outstanding ...

ITIL Service Desk Analyst - Retail Giant (UXBRIDGE)- 25,000k

Please submit your CV today to apply and call Emily Heap on 0207 4466666 to confirm reciept today! The successful candidate will have experience in ...

On The Road Blog

Mobile Linux Better For Mobile Busines...

Mobile Linux Better For Mobile Business Apps? Author: Eric Everson, MyMobiSafe.com As mobile Linux is carving it’s footprint on the future of mobile application development, the... More

Post a comment

First sighting of the Atom Eee?

Pictures purporting to be of the Asus Eee 901 are currently doing the rounds on them intarwebs, and the reaction seems to be mixed. Some people are chuffed that it looks a bit curvier... More

Post a comment

Google and the Atomic iPhone

Much speculation coming out of Germany about the new iPhone, specifically over the issues of screen size and processor. First came a quote from Intel bod Hannes Schwaderer that seemed... More

1 comment