The IEEE Conference on Local Computer Networks 30th Anniversary (LCN'05)l 2005
DOI: 10.1109/lcn.2005.46
|View full text |Cite
|
Sign up to set email alerts
|

Defining and Evaluating Greynets (Sparse Darknets)

Abstract: Darknets are increasingly being proposed as a means by which network administrators can monitor for anomalous, externally sourced traffic. Current darknet designs require large, contiguous blocks of unused IP addresses -not always feasible for enterprise network operators. In this paper we introduce, define and evaluate the concept of a Greynet -a region of IP address space that is sparsely populated with 'darknet' addresses interspersed with active (or 'lit') IP addresses. We use raw traffic traces collected … Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1
1
1

Citation Types

0
9
0

Year Published

2006
2006
2020
2020

Publication Types

Select...
5
3
1

Relationship

0
9

Authors

Journals

citations
Cited by 23 publications
(9 citation statements)
references
References 4 publications
0
9
0
Order By: Relevance
“…For instance, Bailey, et al and Cooke, et al have shown that, with an IPv4 network telescope, much more data is gathered when it is located near live hosts [4,8]. Likewise, Harrop et al discuss, in the context of enterprise IPv4 networks, the advantages of greynets, which have unused addresses interspersed with live addresses to produce visibility similar to that of a large, contiguous network telescope [17]. Since the IPv6 address space is vast, compared to IPv4, (and, consequently, sparse) this locality advantage is even more necessary to capture a network telescope sample of any meaningful size.…”
Section: Complications Of a Covering Prefixmentioning
confidence: 99%
“…For instance, Bailey, et al and Cooke, et al have shown that, with an IPv4 network telescope, much more data is gathered when it is located near live hosts [4,8]. Likewise, Harrop et al discuss, in the context of enterprise IPv4 networks, the advantages of greynets, which have unused addresses interspersed with live addresses to produce visibility similar to that of a large, contiguous network telescope [17]. Since the IPv6 address space is vast, compared to IPv4, (and, consequently, sparse) this locality advantage is even more necessary to capture a network telescope sample of any meaningful size.…”
Section: Complications Of a Covering Prefixmentioning
confidence: 99%
“…Therefore, we demonstrate the usefulness of the proposed approach through a case study on over a year of data. The data was collected from a greynet [37], [7], meaning that the unused IPs are from a network that is populated by both active and unused IP addresses.…”
Section: Analysis Of Darknet Trafficmentioning
confidence: 99%
“…Greynets [35,36] modify the darknet concept by monitoring unused IP addresses diffused amongst 'normal' active IP addresses in an operational enterprise network. Detecting worm scans within an enterprise network is particularly useful for detecting and tracking worms that have taken up residence on 'trusted' hosts inside the enterprise's boundaries.…”
Section: Network Monitoringmentioning
confidence: 99%
“…In recent times, people have explored the use of darknets 1 [41] and greynets [35] to passively monitor for the tell-tale signs of network scans in progress. In this paper we make use of the greynet to provide passively collected network intrusion information.…”
Section: Introductionmentioning
confidence: 99%