You are here: silicon.com > Networks > WebWatch

WebWatch

Internet blacklisting tool unveiled

…taking a page out of Google's book

Tags: google, internet, security

By Matthew Broersma

Published: 28 July 2008 08:44 GMT

Security researchers have taken a page out of Google's book in reinventing the blacklist, a tool for blocking internet attacks.

At this week's 17th Usenix Security Symposium, researchers from the Sans Institute and SRI International will present the results of their experiments with 'highly predictive blacklisting' (HPB), a service that tailors blacklists for particular networks using an approach similar to Google's PageRank. PageRank is Google's technique for making search results more relevant.

Have your say on the state of tech skills in the UK. Take the silicon.com Skills Survey 2008

Take the survey now

The researchers have been investigating HPB since early last year, via an experimental service offered to contributors to DShield.

DShield is a community-based system that collaborates firewall logs from contributors in order to analyse attack trends, and is used as the data-collection system behind the Sans Institute's Internet Storm Center.

DShield and similar sites offer firewall filters enabling administrators to block a list of the internet's worst attackers, known as a 'global worst-offenders list' (GWOL), but this may contain many attacks that the network will simply never encounter, researchers said.

Local networks also create their own local worst-offender lists (LWOLs) but these aren't capable of dealing with attackers that are encountered by that network for the first time.

HPB is designed to be a middle ground between the two. It is based on DShield researchers' finding that groups of networks share various degrees of common attacker overlap: what the researchers called "correlated victims".

By taking this overlap into account, the researchers said they can create blacklists personalised for an individual network that can accurately estimate the probability that a source will attack that network within the next few days.

"In formulating HPB for a network 'A', we treat attack sources that have reportedly made attacks on networks correlated with 'A' differently from attack sources that attacked the same number but uncorrelated networks," researchers said in a document on the website of SRI International's Cyber-Threat Analytics project, which is co-ordinating the HPB research.

The researchers said: "Traditional blacklisting approaches, such as GWOL, treat these two attackers equally, therefore, ignore the characteristics of individual networks shown in the alert history." The project's contributors are SRI's Phillip Porras and Jian Zhang and the Sans Institute's Johannes Ullrich. The algorithm developed by the project appears to significantly improve blacklist accuracy, the researchers said.

"Our experiments show that the HPB exhibits a higher hit count than traditional blacklists for most of the contributors," they noted. "The experiments also show that HPB's performance is consistent over time, and these advantages remain stable across various list lengths and predict windows."

Original article: Researchers redefine the internet blacklist from ZDNet UK

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure
Read and write about internet access at the airports of the world at atlarge.com. Rate airports, and see what others have to say...

Peter Cochrane Peter Cochrane's Blog: Facebook saves teen from prison Another unexpected impact of social networking

Natasha Lomas Exclusive: Jimmy Wales on what's next for Wikipedia Why Wikipedia needs geeks and why a life unplugged is unthinkable


  • Jobs
Senior Software Engineer

These next-generation threats attack on multiple levels of the network infrastructure. CompanyMcAfee creates best-of-breed computer security ...

Linking Strategist, Cornwall; 16K DOE + Benefits

You will have a good understanding of search engines and the workings of Google, Yahoo! An understanding of search engines and the workings of ...

Information Security Analyst

ISO/COBIT/Network/Firewall/PRINCE - 30,000-35,000We are urgently looking for an ISO/COBIT/Network/Firewall/PRINCE Information Security Analyst to ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: