Technology Review - Published By MIT
Advertisement

arXiv blog

The Physics arXiv Blog produces daily coverage of the best new ideas from an online forum called the Physics arXiv on which scientists post early versions of their latest ideas. Contact me at KentuckyFC @ arxivblog.com

Email Subscription

Recently on the arXiv blog...

Recent comments on the arXivblog

  • ... : so funny ! just like http://www.udtek.com
  • Mr CP : Wow!  These games are almost as fun as throwing a real ball around!  Almost.  :)
  • scoubidoo : I suggest you visit the NooJ website: http://www.nooj4nlp.net/pages/nooj.htmland discover the...
  • coolmike : The other issue that is being overlooked is the type of prepaid service, and how the cost impacts...
  • jhertzberg : I checked the date as I read this (nope, not April 1st). How long until we start using...
  • jtempere : Both yttrium barium copper oxide and the family of bismuth strontium calcium copper oxides have...
  • sleeprun : We read a Wharton study of doctors influencing new treatment adoption.  It was not the most...
  • ZephirAWT : isn't completelly new in this context, as the simmilar concept was proposed by Mark Hucko in 1985...
  • ZephirAWT : If I understood it well, by your theory matter universe is surrounded by antimatter universe and...
  • matt_s : Couldn't we theoretically save the earth from the eventual expansion of the sun in it's...
  • ... : This is not about the originators of ideas, but about how the ideas spread. A well connected...
  • debu : Please read my ether-gravity or theory of gravitoethertons which explains many aspects of quantum...
  • ms : So is AMSC selling superconducting wire that doesn't exist?
  • shazl : I believe the results are not only because of somebody being post-paid or pre-paid. It's...
  • ... : I am surprised no one is addressing an immediate need for energy here on earth, and what this...
  • IXANTI666 : THE NEXT STEP HUMAN TELEPORTATION.SINCE WE ARE MADE UP OF QUATUM MATTER TO BEGIN WITH TO BORROW...
  • 020648 : try www.prisonplanet.tv
  • ZephirAWT : And what prohibits scientists in ATTEMPT to replicate J.F.Prins experiments? Are they so...
  • ... : Make me some 90K Tc superconductor and I'll finish my PhD in a month! How's this for a conspiracy...
  • sfrysfry : For ideas on entangling larger structures, I introduce the conjecture of Nicholas Greaves, an...
Advertisement
Tuesday, August 18, 2009

How to Forecast Malicious Internet Attacks

Predictive blacklisting forecasts where your next attack is coming from and blocks the traffic in advance.

There's no shortage of malicious activity on the internet--by some accounts, cyberspace is dominated by it. The question is how to avoid it. Today, computer scientists outline a new way of predicting the next attack so that you can block it in advance.

The new technique builds on perhaps the most common technique for avoiding unwanted internet activity: creating lists of the most prolific attack sources which are compiled, shared and then blocked.

The trouble with blacklists is that it is reactive: it blocks malicious sites after they have attacked. The words stable door and bolted come to mind.

Last year, computer scientists began exploring a potentially more effective approach: predicting the sites most likely to attack and blocking them in advance. The technique, called highly predictive blacklisting, uses data from past attacks to create a network-type graph out of the pattern of links between victims . It then runs a Google PageRank type algorithm for each victim looking for the most relevant attackers. The reuslting list is then used to block potential attackers in future.

Now Fabio Soldo, Anh Le and Athina Markopoulou from the University of California, Irvine say they have a better approach based on recommendation systems. These work by using past behaviour to predict the future.

In the same way that Amazon can recommend a book by comparing your past reading habits to many other individuals, it is possible to predict how you will be targeted by malicious internet activity by comparing your history of attacks with other webusers.

The Irvine team have tested their algorithm on a dataset of 1 month's worth of logs consisting of 100s of millions of security logs from 100s of networks. The team claims that the strike rate of its predictive blacklists is up to 70 per cent better than the state-of-the-art systems and that further improvements are well within reach.

There are some potential problems to iron out. For example. the team isn't quite sure how to handle the constantly changing pattern of malicious attacks and malicious attackers may soon find that it's not too hard to fool recommendation systems if you try hard enough.

Nevertheless, this an impressive result that could be rapidly implemented. And if that happens, recommendation systems may soon be providing you not only with books and movie tips but a happier surfing experience too.

Ref: arxiv.org/abs/0908.2007: Predictive Blacklisting as an Implicit Recommendation System


Comments

Advertisement

Log In

Forgot your password?     Register »
Advertisement
Technology Review January/February 2010

Current Issue

Security in the Ether
Information technology's next grand challenge will be to secure the cloud--and prove we can trust it.
•  Subscribe
Save 36%
•  Table of Contents
•  MIT News
» Gift Subscription
» Digital Subscription
» Reprints, Back Issues
» Subscribe
» Table of Contents
» MIT News

More Technology News from Forbes

Advertisement
MIT Massachusetts Institute of Technology © 2010 Technology Review. All Rights Reserved.