Beneath the Facade of IP Leasing: Graph-Based Approach for Identifying Malicious IP Blocks

被引:0
|
作者
Liu, Zhenni [1 ,2 ]
Sun, Yong [1 ,2 ]
Li, Zhao [1 ,2 ]
Yin, Jiangyi [1 ,2 ]
Liu, Qingyun [1 ,2 ]
机构
[1] Chinese Acad Sci, Inst Informat Engn, Beijing, Peoples R China
[2] Univ Chinese Acad Sci, Sch Cyber Secur, Beijing, Peoples R China
来源
基金
国家重点研发计划;
关键词
IP blocks detection; Graph representation learning;
D O I
10.1007/978-3-031-63759-9_6
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
With the depletion of IPv4 address resources, the prevalence of IPv4 address leasing services by hosting providers has surged. These services allow users to rent IP blocks, offering an affordable and flexible solution compared to traditional IP address allocation. Unfortunately, this convenience has led to an increase in abuse, with illegal users renting IP blocks to host malicious content such as phishing sites and spam services. To mitigate the issue of IP abuse, some research focuses on individual IP identification for point-wise blacklisting. However, this approach leads to a game of whack-a-mole, where blacklisted IPs become transient due to content migration within the IP block. Other studies take a block perspective, recognizing and classifying IP blocks. This enables the discovery of potentially malicious IPs within the block, effectively countering service migration issues. However, existing IP block identification methods face challenges as they rely on specific WHOIS fields, which are sometimes not updated in real-time, leading to inaccuracies. In terms of classification, methods rely on limited statistical features, overlooking vital relationships between IP blocks, making them susceptible to evasion. To address these challenges, we propose BlockFinder, a two-stage framework. The first stage leverages the temporal and spatial stability of services to identify blocks of varying sizes. In the second stage, we introduce an innovative IP block classification model that integrates global node and local subgraph representations to comprehensively learn the graph structure, thereby enhancing evasion difficulty. Experimental results show that our approach achieves state-of-the-art performance.
引用
收藏
页码:46 / 53
页数:8
相关论文
共 50 条
  • [21] An Algorithm for Identifying the Abstract Syntax of Graph-Based Diagrams
    Anaby-Tavor, Ateret
    Amid, David
    Fisher, Amit
    Ossher, Harold
    Bellamy, Rachel
    Callery, Matthew
    Desmond, Michael
    Krasikov, Sophia
    Roth, Tova
    Simmonds, Ian
    de Vries, Jacqueline
    2009 IEEE SYMPOSIUM ON VISUAL LANGUAGES AND HUMAN-CENTRIC COMPUTING, PROCEEDINGS, 2009, : 193 - +
  • [22] A graph-based approach to context matching
    Olaru, Andrei
    Florea, Adina Magda
    Scalable Computing, 2010, 11 (04): : 393 - 400
  • [23] A Graph-Based Approach for Image Segmentation
    Le, Thang V.
    Kulikowski, Casimir A.
    Muchnik, Ilya B.
    ADVANCES IN VISUAL COMPUTING, PT I, PROCEEDINGS, 2008, 5358 : 278 - +
  • [24] A Graph-Based Approach to Feature Selection
    Zhang, Zhihong
    Hancock, Edwin R.
    GRAPH-BASED REPRESENTATIONS IN PATTERN RECOGNITION, 2011, 6658 : 205 - 214
  • [25] A Graph-based approach for Kite recognition
    Madi, Kamel
    Seba, Hamida
    Kheddouci, Hamamache
    Barge, Olivier
    PATTERN RECOGNITION LETTERS, 2017, 87 : 186 - 194
  • [26] A GRAPH-BASED APPROACH FOR SEMISUPERVISED CLUSTERING
    Yoshida, Tetsuya
    COMPUTATIONAL INTELLIGENCE, 2014, 30 (02) : 263 - 284
  • [27] A graph-based approach to inequality assessment
    Palestini, Arsen
    Pignataro, Giuseppe
    PHYSICA A-STATISTICAL MECHANICS AND ITS APPLICATIONS, 2016, 455 : 65 - 78
  • [28] Grid Smoothing: A Graph-Based Approach
    Noel, Guillaume
    Djouani, Karim
    Hamam, Yskandar
    PROGRESS IN PATTERN RECOGNITION, IMAGE ANALYSIS, COMPUTER VISION, AND APPLICATIONS, 2010, 6419 : 153 - 160
  • [29] Graph-based Approach to Reliability Assessment
    Sinitca, Aleksandr M.
    Shalugin, Evgeniy D.
    PROCEEDINGS OF THE 2021 IEEE CONFERENCE OF RUSSIAN YOUNG RESEARCHERS IN ELECTRICAL AND ELECTRONIC ENGINEERING (ELCONRUS), 2021, : 682 - 685
  • [30] A graph-based approach to auditing RxNorm
    Bodenreider, Olivier
    Peters, Lee B.
    JOURNAL OF BIOMEDICAL INFORMATICS, 2009, 42 (03) : 558 - 570