An Internet-Scale Data-Driven Approach for Exploring Cyber Threats Amid Global Conflicts
Where it appeared
| Published in | IEEE Internet of Things Magazine |
|---|
| Publisher | Institute of Electrical and Electronics Engineers |
|---|
| Volume | 8 |
|---|
| Issue | 1 |
|---|
| Pages | 66--72 |
|---|
Abstract
The cyber domain demonstrates a profound interconnection with diverse global events, exerting its influence across social, political, and military realms. As a result, it is both rational and imperative to maintain a keen awareness of the threats that arise within the cyber domain. This can be achieved through robust cyber analytics and data-driven techniques to identify, analyze, and mitigate relevant cyber risks. As such, in this article, we elaborate on a unique, broadly-applicable, empirically-driven capability to enable the consistent measurement, identification and characterization of cyber threat dynamics. Specifically, we investigate and explore Internet-wide empirical data from diverse sources, namely, dark IP address spaces on the Internet to detect backscatter and scanning probes, globally distributed user datagram protocol (UDP) sensors to quantify reflective amplification attempts, and route collectors to ingest Border Gateway Protocol (BGP) routing data. As a case study, throughout an extensive 7-month measurement period, we employ the proposed approach to shed light on the 2022 Russo-Ukrainian cyber threat activities by drawing upon more than 150GB of real network and security data. We infer DDoS and UDP reflective attacks targeting federal agencies in Russia, and media entities in Ukraine. We further perceive an upsurge of Russian and Ukrainian Remotely Triggered Black Hole (RTBH) techniques employed to block attacks targeting multiple Russian " • ru" country code top-level domain (ccTLD) and media companies. Additionally, we uncover an escalation of reconnaissance events, some of which are generated by the IoT-centric Mirai malware and others which target critical infrastructure. We report our findings while postulating thoughts on intriguing observations.