Mapping of Internet "Coastlines" via Large Scale Anonymized Network Source Correlations
Hayden Jananthan, Jeremy Kepner, Michael Jones, William Arcand, David, Bestor, William Bergeron, Chansup Byun, Timothy Davis, Vijay Gadepally,, Daniel Grant, Michael Houle, Matthew Hubbell, Anna Klein, Lauren Milechin,, Guillermo Morales, Andrew Morris, Julie Mullen

TL;DR
This paper analyzes large-scale anonymized Internet traffic data to explore geometric interpretations of traffic distributions, revealing differences between benign and malicious activity that could enhance network security.
Contribution
It introduces a geometric framework based on the Gull lighthouse problem to interpret Internet traffic distributions and applies it to large datasets for network protection insights.
Findings
Confirmed Cauchy-like distributions in Internet traffic
Identified geometric differences between benign and malicious traffic
Proposed a heuristic for classifying traffic based on geometry
Abstract
Expanding the scientific tools available to protect computer networks can be aided by a deeper understanding of the underlying statistical distributions of network traffic and their potential geometric interpretations. Analyses of large scale network observations provide a unique window into studying those underlying statistics. Newly developed GraphBLAS hypersparse matrices and D4M associative array technologies enable the efficient anonymized analysis of network traffic on the scale of trillions of events. This work analyzes over 100,000,000,000 anonymized packets from the largest Internet telescope (CAIDA) and over 10,000,000 anonymized sources from the largest commercial honeyfarm (GreyNoise). Neither CAIDA nor GreyNoise actively emit Internet traffic and provide distinct observations of unsolicited Internet traffic (primarily botnets and scanners). Analysis of these observations…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsInternet Traffic Analysis and Secure E-voting · Complex Network Analysis Techniques · Network Security and Intrusion Detection
