140 likes | 236 Views
Highly Predictive Blacklisting. 5/10 黃瀚嶙. Introduction. GWOL-global worst offender list LWOL-local worst offender list HPB -highly predictive blacklisting. References. Highly Predictive Blacklisting
E N D
Highly Predictive Blacklisting 5/10 黃瀚嶙
Introduction • GWOL-global worst offender list • LWOL-local worst offender list • HPB -highly predictive blacklisting
References • Highly Predictive Blacklisting Jian Zhang, Phillip Porras, and Johannes Ullrich. Highly predictive blacklisting. In Usenix Security Symposium, 2008.
Blacklisting System -Prefiltering Logs • remove invalid or unassigned IP address space -like 10.x.x.x or 192.168.x.x • use the whitelist • exclude specific port -TCP 53 (DNS), 25 (SMTP), 80 (HTTP)…etc
Blacklisting System -Relevance Ranking • relevance vector • Thers is a fast solution like • the rank of a source with respect to different contributors is different
Blacklisting System -Attack Pattern Severity • cm:total num of attack port, cu :total num of unique port • wm, wu : the weight of Cm Cu • TC(s):unique target IP addresses connected to by attacker s. • malware severity score
Blacklisting System -Blacklist Production • final blacklist for each contributor -k :relevance rank of the attacker -L:final list length
Conclusion • new attacker prediction quality • new system to generate blacklists