An Internet-Scale Data-Driven Approach for Exploring Cyber Threats Amid Global Conflicts

The work

AuthorsJoseph Khoury; Christelle Nader; Morteza Safaei Pour; Elias Bou-Harb
Typearticle
Year2025
Also known askhoury2024internetscale
Citekeykhoury2025internetscale

Where it appeared

Published inIEEE Internet of Things Magazine
PublisherInstitute of Electrical and Electronics Engineers
Volume8
Issue1
Pages66--72

Abstract

The cyber domain demonstrates a profound interconnection with diverse global events, exerting its influence across social, political, and military realms. As a result, it is both rational and imperative to maintain a keen awareness of the threats that arise within the cyber domain. This can be achieved through robust cyber analytics and data-driven techniques to identify, analyze, and mitigate relevant cyber risks. As such, in this article, we elaborate on a unique, broadly-applicable, empirically-driven capability to enable the consistent measurement, identification and characterization of cyber threat dynamics. Specifically, we investigate and explore Internet-wide empirical data from diverse sources, namely, dark IP address spaces on the Internet to detect backscatter and scanning probes, globally distributed user datagram protocol (UDP) sensors to quantify reflective amplification attempts, and route collectors to ingest Border Gateway Protocol (BGP) routing data. As a case study, throughout an extensive 7-month measurement period, we employ the proposed approach to shed light on the 2022 Russo-Ukrainian cyber threat activities by drawing upon more than 150GB of real network and security data. We infer DDoS and UDP reflective attacks targeting federal agencies in Russia, and media entities in Ukraine. We further perceive an upsurge of Russian and Ukrainian Remotely Triggered Black Hole (RTBH) techniques employed to block attacks targeting multiple Russian " • ru" country code top-level domain (ccTLD) and media companies. Additionally, we uncover an escalation of reconnaissance events, some of which are generated by the IoT-centric Mirai malware and others which target critical infrastructure. We report our findings while postulating thoughts on intriguing observations.

A copy is held

pdf, 1.5 MB. Not published — it may be under copyright. The facts and links here are.

How it got here

How it got hereagent via openalex
Added2026-08-13 00:00 UTC
Approved bya person 2026-08-14 16:27 UTC

Cite it as

@article{khoury2025internetscale,
  title        = {An Internet-Scale Data-Driven Approach for Exploring Cyber Threats Amid Global Conflicts},
  author       = {Joseph Khoury and Christelle Nader and Morteza Safaei Pour and Elias Bou-Harb},
  year         = {2025},
  journal      = {IEEE Internet of Things Magazine},
  volume       = {8},
  number       = {1},
  pages        = {66--72},
  publisher    = {Institute of Electrical and Electronics Engineers},
  doi          = {10.1109/iotm.001.2400044},
}

This record lives at https://refs.drheap.org/khoury2025internetscale/ and will keep doing so. It used to be called khoury2024internetscale, and those addresses still resolve to this one.