Advertisement
Promo

Security threats Toolkit

Researchers redefine the internet blacklist

Matthew Broersma ZDNet.co.uk

Published: 25 Jul 2008 16:03 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Security researchers have taken a page out of Google's book in reinventing the blacklist, a tool for blocking internet attacks.

At next week's 17th Usenix Security Symposium, researchers from the Sans Institute and SRI International will present the results of their experiments with 'highly predictive blacklisting' (HPB), a service that tailors blacklists for particular networks using an approach similar to Google's PageRank. PageRank is Google's technique for making search results more relevant.

The researchers have been investigating HPB since early last year, via an experimental service offered to contributors to DShield.

DShield is a community-based system that collaborates firewall logs from contributors in order to analyse attack trends, and is used as the data-collection system behind the Sans Institute's Internet Storm Center.

DShield and similar sites offer firewall filters enabling administrators to block a list of the internet's worst attackers, known as a 'global worst-offenders list' (GWOL), but this may contain many attacks that the network will simply never encounter, researchers said.

Local networks also create their own local worst-offender lists (LWOLs), but these aren't capable of dealing with attackers that are encountered by that network for the first time.

HPB is designed to be a middle ground between the two. It is based on DShield researchers' finding that groups of networks share various degrees of common attacker overlap: what the researchers called "correlated victims".

Read this

Comment
Comment: The man who transformed internet security

When security researcher Dan Kaminsky discovered a potentially disastrous flaw within the Domain Name System, his measured response led to the biggest-ever multiparty patch release

Read more +

By taking this overlap into account, the researchers said they can create blacklists personalised for an individual network that can accurately estimate the probability that a source will attack that network within the next few days.

"In formulating HPB for a network 'A', we treat attack sources that have reportedly made attacks on networks correlated with 'A' differently from attack sources that attacked the same number but uncorrelated networks," researchers said in a document on the website of SRI International's Cyber-Threat Analytics project, which is co-ordinating the HPB research.

"Traditional blacklisting approaches, such as GWOL, treat these two attackers equally, therefore, ignore the characteristics of individual networks shown in the alert history," the researchers noted.

The project's contributors are SRI's Phillip Porras and Jian Zhang and the Sans Institute's Johannes Ullrich. The algorithm developed by the project appears to significantly improve blacklist accuracy, the researchers said.

"Our experiments show that the HPB exhibits a higher hit count than traditional blacklists for most of the contributors," they noted. "The experiments also show that HPB's performance is consistent over time, and these advantages remain stable across various list lengths and predict windows."

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Did you find this article useful?
6 out of 6 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:






Video icon

Video

Sentry Posts Blog

Malicious Mobile Apps a Growing Concer...

Malicious Mobile Apps a Growing Concern Author: Eric Everson, MBA, MSIT-SE The phrase “mobile security” does not usually mean much to anyone, until of course they encounter their... More

Post a comment

Malicious Mobile Code: What You Need t...

Malicious Mobile Code: What You Need to Know. Author: Eric Everson, MBA, MSIT-SE The thought of someone hacking into your mobile phone to steal your personal data added to the growing... More

1 comment

Bletchley Park calls for operators for...

The home of World War II codebreaking has called for engineers to operate an electro-mechanical machine developed by mathematician Alan Turing. The Turing Bombe was a brute-force... More

2 comments


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters