Authors
Fabian Fischer, Johannes Fuchs, Pierre-Antoine Vervier, Florian Mansmann, Olivier Thonnard
Publication date
2012/10/15
Book
Proceedings of the ninth international symposium on visualization for cyber security
Pages
80-87
Description
Routing in the Internet is vulnerable to attacks due to the insecure design of the border gateway protocol (BGP). One possible exploitation of this insecure design is the hijacking of IP blocks. Such hijacked IP blocks can then be used to conduct malicious activities from seemingly legitimate IP addresses. In this study we actively trace and monitor the routes to spam sources over several consecutive days after having received a spam message from such a source. However, the real challenge is to distinguish between legitimate routing changes and those ones that are related to systematic misuse in so-called spam campaigns. To combine the strengths of human judgement and computational efficiency, we thus present a novel visual analytics tool named Vistracer in this paper. This tool represents analysis results of our anomaly detection algorithms on large traceroute data sets with the help of several scalable …
Total citations
20132014201520162017201820192020202120222023202446453624731
Scholar articles
F Fischer, J Fuchs, PA Vervier, F Mansmann… - Proceedings of the ninth international symposium on …, 2012