ORION: Observatory for Cyber-Risk Insights and Outages of Networks – UROP Summer Symposium 2022

ORION: Observatory for Cyber-Risk Insights and Outages of Networks

Joshua Peralta

Joshua Peralta photo

Research Mentor(s): Michael Kallitsis
Research Mentor School/College/Department: Merit Network, Inc.
Presentation Date: 08/03/2022
Presentation Type: Poster
Poster Number: 12
Session: Session II: 1:30 – 2:20pm
Room: League Ballroom
Authors: Joshua Peralta, Michalis Kallitsis

Abstract

Network telescopes or “Darknets” collect and record unsolicited Internet traffic destined to unused but routed Internet addresses. They provide a universal perspective on Internet behavior and serve as one of the key sources for network and security analysts when it comes to understanding malware propagation, network scanning, Internet outages, routing misconfigurations, and Distributed Denial of Service (DDoS) attacks. Network operators possess Autonomous System Numbers (ASNs) that identify the group of IP addresses that they run on the Internet. Each ASN is unique and representative of a different company and the Internet space that they manage and use. Project ORION (Observatory for Cyber-Risk Insights and Outages of Networks) organizes and analyzes collected Darknet data into more meaningful events such as Denial of Service attacks or scanning. From this, security analysts can view Internet-wide trends, gain useful insights, and identify any potential threats that exist within their networks and the Internet in general. In this project, we will develop dashboards to help researchers and analysts visualize Darknet data for various ASNs in the form of a Hilbert Curve. Each ASN is compared to its own history of scanning and Darknet activity from the past to determine if any potential security threats or unusual activity exist within the network. As a result of this, security analysts are able to obtain useful insights and information about their Internet space and the type of activity that exists within it. They can then use the data to work toward a solution for any potential threats before they become more of an issue for their network and those who utilize it.

lsa logoum logo