Sciweavers

TON
2012

Abnormally Malicious Autonomous Systems and Their Internet Connectivity

12 years 1 months ago
Abnormally Malicious Autonomous Systems and Their Internet Connectivity
—While many attacks are distributed across botnets, investigators and network operators have recently identified malicious networks through high profile autonomous system (AS) de-peerings and network shut-downs. In this paper, we explore whether some ASes indeed are safe havens for malicious activity. We look for ISPs and ASes that exhibit disproportionately high malicious behavior using ten popular blacklists, plus local spam data, and extensive DNS resolutions based on the contents of the blacklists. We find that some ASes have over 80% of their routable IP address space blacklisted. Yet others account for large fractions of blacklisted IP addresses. Several ASes regularly peer with ASes associated with significant malicious activity. We also find that malicious ASes as a whole differ from benign ones in other properties not obviously related to their malicious activities, such as more frequent connectivity changes with their BGP peers. Overall, we conclude that examining mali...
Craig A. Shue, Andrew J. Kalafut, Minaxi Gupta
Added 28 Sep 2012
Updated 28 Sep 2012
Type Journal
Year 2012
Where TON
Authors Craig A. Shue, Andrew J. Kalafut, Minaxi Gupta
Comments (0)