Download presentation
Presentation is loading. Please wait.
1
Questions on “Data Reduction for the Scalable Automated Analysis of Distributed Darknet Traffic” Yao Zhao
2
Hybrid Architecture IMS + HMS IMS Proxy back to HMS –Detectable by delay
3
Filtering with First Payload Only use hash of the payload –A little bit change in the first payload will escape –Polymorphic worms
4
Collaboration Works? The IDS collaboration paper tells that collaboration helps much This paper tries to say collaboration of darknet doesn’t make much sense.
5
Duration of Event Figure 8 Obtained from one honeypot host Heavy tail? Long durations –A single /17 darknet block need to handle from 40,000 to 200,000 simultaneous connections –But session <> infection session
6
Different Scale of Darknets
Similar presentations
© 2024 SlidePlayer.com. Inc.
All rights reserved.