06 - Creating a Network Reputation Database

Václav Bartoš (CESNET)

NRENs often operate various network monitoring tools which are able to detect diverse security incidents. Project Reputation Shield, introduced in this presentation, aims at gathering reports from large amount of such detectors and leveraging the information to create a comprehensive database of known misbehaving entities on the Internet. We will present selected interesting characteristics of malicious traffic and its sources, as well as the design of the database and algorithms for estimating reputation of network entities.

