Skip to main content
U.S. Department of Energy
Office of Scientific and Technical Information

Big Data Sanitization and Cyber Situational Awareness: A Network Telescope Perspective

Journal Article · · IEEE Transactions on Big Data

This paper addresses the problems of data sanitization and cyber situational awareness by analyzing 910 GB of real Internet-scale traffic, which has been passively collected by monitoring close to 16.5 million darknet IP addresses from a /8 and a /13 network telescopes. First, the paper offers a novel probabilistic darknet preprocessing model, which aims at sanitizing darknet data to prepare it for effective use in the task of cyber threat intelligence generation. Such model has been engineered using a distributed multithreaded approach, rendering it highly effective on darknet big data. Second, the paper further contributes by presenting an innovative approach to infer large-scale orchestrated probing campaigns by leveraging darknet data, for Internet cyber situational awareness. The approach uniquely reduces the dimensionality of such big data by utilizing its artifacts, instead of processing the actual raw data. This is accomplished by extracting and analyzing probing time series using formal methods rooted in Fourier transform and Kalman filtering. Thorough empirical evaluations indeed validate the accuracy and the performance of the proposed methods. We assert that such approaches are of significant value, given their highly applicable nature to the field of Internet measurements for cyber security in the era of big data.

Research Organization:
Lawrence Berkeley National Laboratory (LBNL), Berkeley, CA (United States). National Energy Research Scientific Computing Center (NERSC)
Sponsoring Organization:
USDOE
OSTI ID:
1544383
Journal Information:
IEEE Transactions on Big Data, Journal Name: IEEE Transactions on Big Data; ISSN 2332-7790
Publisher:
IEEE
Country of Publication:
United States
Language:
English

Similar Records

Situational Awareness as a Measure of Performance in Cyber Security Collaborative Work
Conference · Mon Apr 11 00:00:00 EDT 2011 · OSTI ID:1043138

Gamification for Measuring Cyber Security Situational Awareness
Conference · Thu Feb 28 23:00:00 EST 2013 · OSTI ID:1144837

Deep Cyber-Physical Situational Awareness for Energy Systems: A Secure Foundation for Next-Generation Energy Management
Technical Report · Mon Jan 27 23:00:00 EST 2025 · OSTI ID:2511304

Related Subjects