A framework for the application of network telescope sensors in a global IP network

dc.contributor.advisorWells, George
dc.contributor.advisorClayton, Peter
dc.contributor.authorIrwin, Barry Vivian William
dc.date.accessioned2026-03-04T07:57:26Z
dc.date.issued2011
dc.description.abstractThe use of Network Telescope systems has become increasingly popular amongst security researchers in recent years. This study provides a framework for the utilisation of this data. The research is based on a primary dataset of 40 million events spanning 50 months collected using a small (/24) passive network telescope located in African IP space. This research presents a number of differing ways in which the data can be analysed ranging from low level protocol based analysis to higher level analysis at the geopolitical and network topology level. Anomalous traffic and illustrative anecdotes are explored in detail and highlighted. A discussion relating to bogon traffic observed is also presented. Two novel visualisation tools are presented, which were developed to aid in the analysis of large network telescope datasets. The first is a three-dimensional visualisation tool which allows for live, near-realtime analysis, and the second is a two-dimensional fractal based plotting scheme which allows for plots of the entire IPv4 address space to be produced, and manipulated. Using the techniques and tools developed for the analysis of this dataset, a detailed analysis of traffic recorded as destined for port 445/tcp is presented. This includes the evaluation of traffic surrounding the outbreak of the Conficker worm in November 2008. A number of metrics relating to the description and quantification of network telescope configuration and the resultant traffic captures are described, the use of which it is hoped will facilitate greater and easier collaboration among researchers utilising this network security technology. The research concludes with suggestions relating to other applications of the data and intelligence that can be extracted from network telescopes, and their use as part of an organisation's integrated network security systems
dc.description.degreeDoctoral thesis
dc.description.degreePhD
dc.format.extent327 pages
dc.format.mimetypeapplication/pdf
dc.identifier.otherhttp://hdl.handle.net/10962/d1004835
dc.identifier.urihttps://researchrepository.ru.ac.za/handle/123456789/5340
dc.languageEnglish
dc.publisherRhodes University, Faculty of Science, Department of Computer Science
dc.rightsIrwin, Barry Vivian William
dc.subjectSensor networks
dc.subjectComputer networks
dc.subjectTCP/IP (Computer network protocol)
dc.subjectInternet
dc.subjectComputer security
dc.subjectComputers -- Access control
dc.subjectComputer networks -- Security measures
dc.subjectComputer viruses
dc.subjectMalware (Computer software)
dc.titleA framework for the application of network telescope sensors in a global IP network
dc.typeAcademic thesis

Files

Original bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
A_framework_for_the_application_of_network_telesco_vital_4593.pdf
Size:
4.1 MB
Format:
Adobe Portable Document Format