Advertisement
Promo

Network management Toolkit

Download now

On the Design and Use of Internet Sinks for Network Abuse Monitoring

PublisherUniversity of Wisconsin
Format338.3KB PDFDate added23 Feb 2005
Topics Monitoring Systems, Network Design
Downloads3

Monitoring unused or dark IP addresses offers opportunities to significantly improve and expand knowledge of abuse activity without many of the problems associated with typical network intrusion detection and firewall systems. This paper addresses the problem of designing and deploying a system for monitoring large unused address spaces such as class A telescopes with 16M IP addresses. The paper describes the architecture and implementation of the Internet Sink (iSink) system which measures packet traffic on unused IP addresses in an efficient, extensible and scalable fashion. In contrast to traditional intrusion detection systems or firewalls, iSink includes an active component that generates response packets to incoming traffic. This gives the iSink an important advantage in discriminating between different types of attacks (through examination of the response payloads).

Download now

Did you find this white paper useful?
10 out of 18 users found this white paper useful


  • Trackback
  • Clip Link

Related white papers

Systems Integration

Many compaines realise the market has changed, the competition is stronger, pressure is on and costs are increasing causing IT structures to change. Every company has it's own indivdual challenges...


How a Spanning Tree Works

The way a switch learns Ethernet (MAC) addresses is by inspecting the Ethernet frame and recording the source MAC address in a dynamic table. The switch will also associate a...


TANDBERG SNMP

The Codec supports the SNMP (Simple Network Management Protocol) standard for network management and surveillance. SNMP is the de facto standard in network management for IP-based units in a network....


Generate Savings Now: The Advantages of Telecom Expense Management

Why is telecom expense management (TEM) gaining importance today? What return on investment can your company expect from TEM? Interested in learning helpful tips for making the business case for...


Channel Sampling Strategies for Monitoring Wireless Networks

Monitoring the activity on an IEEE 802.11 network is useful for many applications, such as network management, optimizing deployment, or detecting network attacks. Deploying wireless sniffers to monitor every access...


BMC Performance ManagerĀ 

BMC Introduces the BMC Performance Manager, the next generation of systems management solutions from BMC and the evolution of PATROL. BMC Performance Manager is an innovative, single, integrated solution that...


Toronto Airport Meets ITIL Standards and Takes Support Levels, Change Management to New Heights With HEAT

The Greater Toronto Airports Authority (GTAA), formed in 1993, is a nonprofit corporation responsible for ensuring that the greater Toronto's regional system of airports meets current and future air service...


White Paper

Featured White Paper

Selecting a Microsoft Hosted Exchange Service Provider

When it comes to the decision to outsource the delivery of your organisation's messaging solution, the task of selecting the most appropriate service provider can be daunting This whitepaper from Cobweb Solutions, Europe's leading Microsoft Hosted Exchange provider, is designed to help simplify that task for you, by arming you with the important ...

Download Now

Other White Papers

Business Efficiency in Unprecedented Times

In these unprecedented times, organisations are left with no choice but to seek out more and more...

Desktop Virtualization on IBM BladeCenter and System x Servers: Taking Back Control of the Desktop

"Operational efficiency is imperative in today's competitive marketplace. Thus, the IT strategies...

See All White Papers

Video icon

Video


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters