Repository files navigation

The Attacker IP Prioritizer (AIP)

version 2.1.0 (2022)

The Idea

The Attacker IP Prioritizer (AIP) algorithm aims to generate a IoT friendly blocklist. With the advent of 5G, many IoT devices are going to be directly connected to the internet instead of being protected by a routers firewall. Therefore we need blocklists that are small and portable, and designed to blocklist IPs that are targeting IoT. The IPs of interest, from a statistics point of view, should have a couple of recognizable features:

First, they should be attacking more often than other IPs. In terms of our collected training data, we increase the priority of the IPs that attack more.

Second, IPs should attack consistently. Namely, IPs should have a higher daily average of attacks and its standard deviation should be lower.

Third, the average duration of the attacks should be longer. This is simply because larger and more advanced botnets are more organized and thorough, thus meaning they need to try more things once they get into our honeypots, thus increasing the length of their events.

Fourth, IPs should be currently active. An IP that was last seen a few months ago would have its priority decreased in our list.

Fifth, the number of bytes transferred and the number of packets sent and received will be greater.

All five of these traits need to be included in the sorting process of AIP and each of them needs to be weighted since they are not of equal importance. Therefore, there is a need to build a prioritization algorithm that receives data flows and outputs information built on top of these six characteristics.

Data Source

The program accepts a directory that contains data files from each day. You assign a directory for the program to look in every time it runs, and it checks if there are any new files to process. If there are, it processes the new files and remembers the names of the new files so that it does not process it the next time it runs.

In terms of file format, it accepts a .csv file that has one IP per line, with each of the following data inputs for each IP on that line, separated by commas:

Amount of events - Meaning the total connections to our honeypots originating from the given IP
Total Duration - How long did this IP connect for the total of its events
Average duration - The average length in seconds of all the connections per IP
Amount of Bytes - Total bytes sent and received
Average number of bytes - For bytes transferred in each connection per IP
Total packets - Of all the connections per IP
Average packets - Average packets sent per connection
Last event time - UNIX time of the last time the IP tried to connect to something in the last 24 hours
First event time - UNIX time of the first time the IP tried to connect in the last 24 hours

For example, a single line in the file could look like this:

"IPv4 Addrss",26049,"7415310","284.6","41808957","1605.0",284577,"10.92","157899154","1578968762.519"

The AIP Algorithm

The AIP algorithm takes each of the flows from the input and uses its data to calculate eight values for each IP. The first seven values from the input data remain unchanged, number of events, total duration, average duration, number of bytes, the average number of bytes, total packets and average packets. However, the first event time and the number of events are used to calculate the average number of events per day the IP has had since it was first seen by the program, giving us a total of eight features as input for our algorithm.

For each IP, each of the eight values is updated using the data from the current day and then saved to a file, called the absolute file. The absolute data file contains the values for all the IPs seen since the program was started.

The next step is to feed the absolute data file, which has been updated with the last 24 hours of events, into the rating program. The rating program assigns each of the eight values a specific weight. These weights control the effect each value will have on the final score. The sum of all weights is one.

Each feature is multiplied by its weight and then summed with the rest, as in a basic linear combination. Then the sum is multiplied by a time modifier. The program currently has three different modules each with its own time modifier, one prioritizing historically aggressive IPs, one prioritizing newer aggressive IPs and one only dealing with IPs seen in the last 24 hours.

Documentation

Click here to check some examples of how the tool is used and the data models.

About

The Attacker IP Prioritizer(AIP) algorithm is a python program designed to dynamically generate a resource-friendly IPv4 address blacklist based on data collected from attacks on a network.

Resources

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Repository files navigation

The Attacker IP Prioritizer (AIP)

version 2.1.0 (2022)

The Idea

The Attacker IP Prioritizer (AIP) algorithm aims to generate a IoT friendly blocklist. With the advent of 5G, many IoT devices are going to be directly connected to the internet instead of being protected by a routers firewall. Therefore we need blocklists that are small and portable, and designed to blocklist IPs that are targeting IoT. The IPs of interest, from a statistics point of view, should have a couple of recognizable features:

First, they should be attacking more often than other IPs. In terms of our collected training data, we increase the priority of the IPs that attack more.

Second, IPs should attack consistently. Namely, IPs should have a higher daily average of attacks and its standard deviation should be lower.

Third, the average duration of the attacks should be longer. This is simply because larger and more advanced botnets are more organized and thorough, thus meaning they need to try more things once they get into our honeypots, thus increasing the length of their events.

Fourth, IPs should be currently active. An IP that was last seen a few months ago would have its priority decreased in our list.

Fifth, the number of bytes transferred and the number of packets sent and received will be greater.

All five of these traits need to be included in the sorting process of AIP and each of them needs to be weighted since they are not of equal importance. Therefore, there is a need to build a prioritization algorithm that receives data flows and outputs information built on top of these six characteristics.

Data Source

The program accepts a directory that contains data files from each day. You assign a directory for the program to look in every time it runs, and it checks if there are any new files to process. If there are, it processes the new files and remembers the names of the new files so that it does not process it the next time it runs.

In terms of file format, it accepts a .csv file that has one IP per line, with each of the following data inputs for each IP on that line, separated by commas:

Amount of events - Meaning the total connections to our honeypots originating from the given IP
Total Duration - How long did this IP connect for the total of its events
Average duration - The average length in seconds of all the connections per IP
Amount of Bytes - Total bytes sent and received
Average number of bytes - For bytes transferred in each connection per IP
Total packets - Of all the connections per IP
Average packets - Average packets sent per connection
Last event time - UNIX time of the last time the IP tried to connect to something in the last 24 hours
First event time - UNIX time of the first time the IP tried to connect in the last 24 hours

For example, a single line in the file could look like this:

"IPv4 Addrss",26049,"7415310","284.6","41808957","1605.0",284577,"10.92","157899154","1578968762.519"

The AIP Algorithm

The AIP algorithm takes each of the flows from the input and uses its data to calculate eight values for each IP. The first seven values from the input data remain unchanged, number of events, total duration, average duration, number of bytes, the average number of bytes, total packets and average packets. However, the first event time and the number of events are used to calculate the average number of events per day the IP has had since it was first seen by the program, giving us a total of eight features as input for our algorithm.

For each IP, each of the eight values is updated using the data from the current day and then saved to a file, called the absolute file. The absolute data file contains the values for all the IPs seen since the program was started.

The next step is to feed the absolute data file, which has been updated with the last 24 hours of events, into the rating program. The rating program assigns each of the eight values a specific weight. These weights control the effect each value will have on the final score. The sum of all weights is one.

Each feature is multiplied by its weight and then summed with the rest, as in a basic linear combination. Then the sum is multiplied by a time modifier. The program currently has three different modules each with its own time modifier, one prioritizing historically aggressive IPs, one prioritizing newer aggressive IPs and one only dealing with IPs seen in the last 24 hours.

Documentation

Click here to check some examples of how the tool is used and the data models.

About

The Attacker IP Prioritizer(AIP) algorithm is a python program designed to dynamically generate a resource-friendly IPv4 address blacklist based on data collected from attacks on a network.

Resources

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

The Attacker IP Prioritizer (AIP)

version 2.1.0 (2022)

The Idea

The Attacker IP Prioritizer (AIP) algorithm aims to generate a IoT friendly blocklist. With the advent of 5G, many IoT devices are going to be directly connected to the internet instead of being protected by a routers firewall. Therefore we need blocklists that are small and portable, and designed to blocklist IPs that are targeting IoT. The IPs of interest, from a statistics point of view, should have a couple of recognizable features:

First, they should be attacking more often than other IPs. In terms of our collected training data, we increase the priority of the IPs that attack more.

Second, IPs should attack consistently. Namely, IPs should have a higher daily average of attacks and its standard deviation should be lower.

Third, the average duration of the attacks should be longer. This is simply because larger and more advanced botnets are more organized and thorough, thus meaning they need to try more things once they get into our honeypots, thus increasing the length of their events.

Fourth, IPs should be currently active. An IP that was last seen a few months ago would have its priority decreased in our list.

Fifth, the number of bytes transferred and the number of packets sent and received will be greater.

All five of these traits need to be included in the sorting process of AIP and each of them needs to be weighted since they are not of equal importance. Therefore, there is a need to build a prioritization algorithm that receives data flows and outputs information built on top of these six characteristics.

Data Source

The program accepts a directory that contains data files from each day. You assign a directory for the program to look in every time it runs, and it checks if there are any new files to process. If there are, it processes the new files and remembers the names of the new files so that it does not process it the next time it runs.

In terms of file format, it accepts a .csv file that has one IP per line, with each of the following data inputs for each IP on that line, separated by commas:

Amount of events - Meaning the total connections to our honeypots originating from the given IP
Total Duration - How long did this IP connect for the total of its events
Average duration - The average length in seconds of all the connections per IP
Amount of Bytes - Total bytes sent and received
Average number of bytes - For bytes transferred in each connection per IP
Total packets - Of all the connections per IP
Average packets - Average packets sent per connection
Last event time - UNIX time of the last time the IP tried to connect to something in the last 24 hours
First event time - UNIX time of the first time the IP tried to connect in the last 24 hours

For example, a single line in the file could look like this:

"IPv4 Addrss",26049,"7415310","284.6","41808957","1605.0",284577,"10.92","157899154","1578968762.519"

The AIP Algorithm

The AIP algorithm takes each of the flows from the input and uses its data to calculate eight values for each IP. The first seven values from the input data remain unchanged, number of events, total duration, average duration, number of bytes, the average number of bytes, total packets and average packets. However, the first event time and the number of events are used to calculate the average number of events per day the IP has had since it was first seen by the program, giving us a total of eight features as input for our algorithm.

For each IP, each of the eight values is updated using the data from the current day and then saved to a file, called the absolute file. The absolute data file contains the values for all the IPs seen since the program was started.

The next step is to feed the absolute data file, which has been updated with the last 24 hours of events, into the rating program. The rating program assigns each of the eight values a specific weight. These weights control the effect each value will have on the final score. The sum of all weights is one.

Each feature is multiplied by its weight and then summed with the rest, as in a basic linear combination. Then the sum is multiplied by a time modifier. The program currently has three different modules each with its own time modifier, one prioritizing historically aggressive IPs, one prioritizing newer aggressive IPs and one only dealing with IPs seen in the last 24 hours.

Documentation

Click here to check some examples of how the tool is used and the data models.

About

The Attacker IP Prioritizer(AIP) algorithm is a python program designed to dynamically generate a resource-friendly IPv4 address blacklist based on data collected from attacks on a network.

Resources

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

The Attacker IP Prioritizer (AIP)

version 2.1.0 (2022)

The Idea

The Attacker IP Prioritizer (AIP) algorithm aims to generate a IoT friendly blocklist. With the advent of 5G, many IoT devices are going to be directly connected to the internet instead of being protected by a routers firewall. Therefore we need blocklists that are small and portable, and designed to blocklist IPs that are targeting IoT. The IPs of interest, from a statistics point of view, should have a couple of recognizable features:

First, they should be attacking more often than other IPs. In terms of our collected training data, we increase the priority of the IPs that attack more.

Second, IPs should attack consistently. Namely, IPs should have a higher daily average of attacks and its standard deviation should be lower.

Third, the average duration of the attacks should be longer. This is simply because larger and more advanced botnets are more organized and thorough, thus meaning they need to try more things once they get into our honeypots, thus increasing the length of their events.

Fourth, IPs should be currently active. An IP that was last seen a few months ago would have its priority decreased in our list.

Fifth, the number of bytes transferred and the number of packets sent and received will be greater.

All five of these traits need to be included in the sorting process of AIP and each of them needs to be weighted since they are not of equal importance. Therefore, there is a need to build a prioritization algorithm that receives data flows and outputs information built on top of these six characteristics.

Data Source

The program accepts a directory that contains data files from each day. You assign a directory for the program to look in every time it runs, and it checks if there are any new files to process. If there are, it processes the new files and remembers the names of the new files so that it does not process it the next time it runs.

In terms of file format, it accepts a .csv file that has one IP per line, with each of the following data inputs for each IP on that line, separated by commas:

Amount of events - Meaning the total connections to our honeypots originating from the given IP
Total Duration - How long did this IP connect for the total of its events
Average duration - The average length in seconds of all the connections per IP
Amount of Bytes - Total bytes sent and received
Average number of bytes - For bytes transferred in each connection per IP
Total packets - Of all the connections per IP
Average packets - Average packets sent per connection
Last event time - UNIX time of the last time the IP tried to connect to something in the last 24 hours
First event time - UNIX time of the first time the IP tried to connect in the last 24 hours

For example, a single line in the file could look like this:

"IPv4 Addrss",26049,"7415310","284.6","41808957","1605.0",284577,"10.92","157899154","1578968762.519"

The AIP Algorithm

The AIP algorithm takes each of the flows from the input and uses its data to calculate eight values for each IP. The first seven values from the input data remain unchanged, number of events, total duration, average duration, number of bytes, the average number of bytes, total packets and average packets. However, the first event time and the number of events are used to calculate the average number of events per day the IP has had since it was first seen by the program, giving us a total of eight features as input for our algorithm.

For each IP, each of the eight values is updated using the data from the current day and then saved to a file, called the absolute file. The absolute data file contains the values for all the IPs seen since the program was started.

The next step is to feed the absolute data file, which has been updated with the last 24 hours of events, into the rating program. The rating program assigns each of the eight values a specific weight. These weights control the effect each value will have on the final score. The sum of all weights is one.

Each feature is multiplied by its weight and then summed with the rest, as in a basic linear combination. Then the sum is multiplied by a time modifier. The program currently has three different modules each with its own time modifier, one prioritizing historically aggressive IPs, one prioritizing newer aggressive IPs and one only dealing with IPs seen in the last 24 hours.

Documentation

Click here to check some examples of how the tool is used and the data models.

About

The Attacker IP Prioritizer(AIP) algorithm is a python program designed to dynamically generate a resource-friendly IPv4 address blacklist based on data collected from attacks on a network.

Resources

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Repository files navigation

The Attacker IP Prioritizer (AIP)

version 2.1.0 (2022)

The Idea

The Attacker IP Prioritizer (AIP) algorithm aims to generate a IoT friendly blocklist. With the advent of 5G, many IoT devices are going to be directly connected to the internet instead of being protected by a routers firewall. Therefore we need blocklists that are small and portable, and designed to blocklist IPs that are targeting IoT. The IPs of interest, from a statistics point of view, should have a couple of recognizable features:

First, they should be attacking more often than other IPs. In terms of our collected training data, we increase the priority of the IPs that attack more.

Second, IPs should attack consistently. Namely, IPs should have a higher daily average of attacks and its standard deviation should be lower.

Third, the average duration of the attacks should be longer. This is simply because larger and more advanced botnets are more organized and thorough, thus meaning they need to try more things once they get into our honeypots, thus increasing the length of their events.

Fourth, IPs should be currently active. An IP that was last seen a few months ago would have its priority decreased in our list.

Fifth, the number of bytes transferred and the number of packets sent and received will be greater.

All five of these traits need to be included in the sorting process of AIP and each of them needs to be weighted since they are not of equal importance. Therefore, there is a need to build a prioritization algorithm that receives data flows and outputs information built on top of these six characteristics.

Data Source

The program accepts a directory that contains data files from each day. You assign a directory for the program to look in every time it runs, and it checks if there are any new files to process. If there are, it processes the new files and remembers the names of the new files so that it does not process it the next time it runs.

In terms of file format, it accepts a .csv file that has one IP per line, with each of the following data inputs for each IP on that line, separated by commas:

Amount of events - Meaning the total connections to our honeypots originating from the given IP
Total Duration - How long did this IP connect for the total of its events
Average duration - The average length in seconds of all the connections per IP
Amount of Bytes - Total bytes sent and received
Average number of bytes - For bytes transferred in each connection per IP
Total packets - Of all the connections per IP
Average packets - Average packets sent per connection
Last event time - UNIX time of the last time the IP tried to connect to something in the last 24 hours
First event time - UNIX time of the first time the IP tried to connect in the last 24 hours

For example, a single line in the file could look like this:

"IPv4 Addrss",26049,"7415310","284.6","41808957","1605.0",284577,"10.92","157899154","1578968762.519"

The AIP Algorithm

The AIP algorithm takes each of the flows from the input and uses its data to calculate eight values for each IP. The first seven values from the input data remain unchanged, number of events, total duration, average duration, number of bytes, the average number of bytes, total packets and average packets. However, the first event time and the number of events are used to calculate the average number of events per day the IP has had since it was first seen by the program, giving us a total of eight features as input for our algorithm.

For each IP, each of the eight values is updated using the data from the current day and then saved to a file, called the absolute file. The absolute data file contains the values for all the IPs seen since the program was started.

The next step is to feed the absolute data file, which has been updated with the last 24 hours of events, into the rating program. The rating program assigns each of the eight values a specific weight. These weights control the effect each value will have on the final score. The sum of all weights is one.

Each feature is multiplied by its weight and then summed with the rest, as in a basic linear combination. Then the sum is multiplied by a time modifier. The program currently has three different modules each with its own time modifier, one prioritizing historically aggressive IPs, one prioritizing newer aggressive IPs and one only dealing with IPs seen in the last 24 hours.

Documentation

Click here to check some examples of how the tool is used and the data models.

About

The Attacker IP Prioritizer(AIP) algorithm is a python program designed to dynamically generate a resource-friendly IPv4 address blacklist based on data collected from attacks on a network.

Resources

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

The Attacker IP Prioritizer (AIP)

version 2.1.0 (2022)

The Idea

The Attacker IP Prioritizer (AIP) algorithm aims to generate a IoT friendly blocklist. With the advent of 5G, many IoT devices are going to be directly connected to the internet instead of being protected by a routers firewall. Therefore we need blocklists that are small and portable, and designed to blocklist IPs that are targeting IoT. The IPs of interest, from a statistics point of view, should have a couple of recognizable features:

First, they should be attacking more often than other IPs. In terms of our collected training data, we increase the priority of the IPs that attack more.

Second, IPs should attack consistently. Namely, IPs should have a higher daily average of attacks and its standard deviation should be lower.

Third, the average duration of the attacks should be longer. This is simply because larger and more advanced botnets are more organized and thorough, thus meaning they need to try more things once they get into our honeypots, thus increasing the length of their events.

Fourth, IPs should be currently active. An IP that was last seen a few months ago would have its priority decreased in our list.

Fifth, the number of bytes transferred and the number of packets sent and received will be greater.

All five of these traits need to be included in the sorting process of AIP and each of them needs to be weighted since they are not of equal importance. Therefore, there is a need to build a prioritization algorithm that receives data flows and outputs information built on top of these six characteristics.

Data Source

The program accepts a directory that contains data files from each day. You assign a directory for the program to look in every time it runs, and it checks if there are any new files to process. If there are, it processes the new files and remembers the names of the new files so that it does not process it the next time it runs.

In terms of file format, it accepts a .csv file that has one IP per line, with each of the following data inputs for each IP on that line, separated by commas:

Amount of events - Meaning the total connections to our honeypots originating from the given IP
Total Duration - How long did this IP connect for the total of its events
Average duration - The average length in seconds of all the connections per IP
Amount of Bytes - Total bytes sent and received
Average number of bytes - For bytes transferred in each connection per IP
Total packets - Of all the connections per IP
Average packets - Average packets sent per connection
Last event time - UNIX time of the last time the IP tried to connect to something in the last 24 hours
First event time - UNIX time of the first time the IP tried to connect in the last 24 hours

For example, a single line in the file could look like this:

"IPv4 Addrss",26049,"7415310","284.6","41808957","1605.0",284577,"10.92","157899154","1578968762.519"

The AIP Algorithm

The AIP algorithm takes each of the flows from the input and uses its data to calculate eight values for each IP. The first seven values from the input data remain unchanged, number of events, total duration, average duration, number of bytes, the average number of bytes, total packets and average packets. However, the first event time and the number of events are used to calculate the average number of events per day the IP has had since it was first seen by the program, giving us a total of eight features as input for our algorithm.

For each IP, each of the eight values is updated using the data from the current day and then saved to a file, called the absolute file. The absolute data file contains the values for all the IPs seen since the program was started.

The next step is to feed the absolute data file, which has been updated with the last 24 hours of events, into the rating program. The rating program assigns each of the eight values a specific weight. These weights control the effect each value will have on the final score. The sum of all weights is one.

Each feature is multiplied by its weight and then summed with the rest, as in a basic linear combination. Then the sum is multiplied by a time modifier. The program currently has three different modules each with its own time modifier, one prioritizing historically aggressive IPs, one prioritizing newer aggressive IPs and one only dealing with IPs seen in the last 24 hours.

Documentation

Click here to check some examples of how the tool is used and the data models.

About

The Attacker IP Prioritizer(AIP) algorithm is a python program designed to dynamically generate a resource-friendly IPv4 address blacklist based on data collected from attacks on a network.

Resources

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

The Attacker IP Prioritizer (AIP)

version 2.1.0 (2022)

The Idea

The Attacker IP Prioritizer (AIP) algorithm aims to generate a IoT friendly blocklist. With the advent of 5G, many IoT devices are going to be directly connected to the internet instead of being protected by a routers firewall. Therefore we need blocklists that are small and portable, and designed to blocklist IPs that are targeting IoT. The IPs of interest, from a statistics point of view, should have a couple of recognizable features:

First, they should be attacking more often than other IPs. In terms of our collected training data, we increase the priority of the IPs that attack more.

Second, IPs should attack consistently. Namely, IPs should have a higher daily average of attacks and its standard deviation should be lower.

Third, the average duration of the attacks should be longer. This is simply because larger and more advanced botnets are more organized and thorough, thus meaning they need to try more things once they get into our honeypots, thus increasing the length of their events.

Fourth, IPs should be currently active. An IP that was last seen a few months ago would have its priority decreased in our list.

Fifth, the number of bytes transferred and the number of packets sent and received will be greater.

All five of these traits need to be included in the sorting process of AIP and each of them needs to be weighted since they are not of equal importance. Therefore, there is a need to build a prioritization algorithm that receives data flows and outputs information built on top of these six characteristics.

Data Source

The program accepts a directory that contains data files from each day. You assign a directory for the program to look in every time it runs, and it checks if there are any new files to process. If there are, it processes the new files and remembers the names of the new files so that it does not process it the next time it runs.

In terms of file format, it accepts a .csv file that has one IP per line, with each of the following data inputs for each IP on that line, separated by commas:

Amount of events - Meaning the total connections to our honeypots originating from the given IP
Total Duration - How long did this IP connect for the total of its events
Average duration - The average length in seconds of all the connections per IP
Amount of Bytes - Total bytes sent and received
Average number of bytes - For bytes transferred in each connection per IP
Total packets - Of all the connections per IP
Average packets - Average packets sent per connection
Last event time - UNIX time of the last time the IP tried to connect to something in the last 24 hours
First event time - UNIX time of the first time the IP tried to connect in the last 24 hours

For example, a single line in the file could look like this:

"IPv4 Addrss",26049,"7415310","284.6","41808957","1605.0",284577,"10.92","157899154","1578968762.519"

The AIP Algorithm

The AIP algorithm takes each of the flows from the input and uses its data to calculate eight values for each IP. The first seven values from the input data remain unchanged, number of events, total duration, average duration, number of bytes, the average number of bytes, total packets and average packets. However, the first event time and the number of events are used to calculate the average number of events per day the IP has had since it was first seen by the program, giving us a total of eight features as input for our algorithm.

For each IP, each of the eight values is updated using the data from the current day and then saved to a file, called the absolute file. The absolute data file contains the values for all the IPs seen since the program was started.

The next step is to feed the absolute data file, which has been updated with the last 24 hours of events, into the rating program. The rating program assigns each of the eight values a specific weight. These weights control the effect each value will have on the final score. The sum of all weights is one.

Each feature is multiplied by its weight and then summed with the rest, as in a basic linear combination. Then the sum is multiplied by a time modifier. The program currently has three different modules each with its own time modifier, one prioritizing historically aggressive IPs, one prioritizing newer aggressive IPs and one only dealing with IPs seen in the last 24 hours.

Documentation

Click here to check some examples of how the tool is used and the data models.

About

The Attacker IP Prioritizer(AIP) algorithm is a python program designed to dynamically generate a resource-friendly IPv4 address blacklist based on data collected from attacks on a network.

Resources

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Repository files navigation

The Attacker IP Prioritizer (AIP)

version 2.1.0 (2022)

The Idea

The Attacker IP Prioritizer (AIP) algorithm aims to generate a IoT friendly blocklist. With the advent of 5G, many IoT devices are going to be directly connected to the internet instead of being protected by a routers firewall. Therefore we need blocklists that are small and portable, and designed to blocklist IPs that are targeting IoT. The IPs of interest, from a statistics point of view, should have a couple of recognizable features:

First, they should be attacking more often than other IPs. In terms of our collected training data, we increase the priority of the IPs that attack more.

Second, IPs should attack consistently. Namely, IPs should have a higher daily average of attacks and its standard deviation should be lower.

Third, the average duration of the attacks should be longer. This is simply because larger and more advanced botnets are more organized and thorough, thus meaning they need to try more things once they get into our honeypots, thus increasing the length of their events.

Fourth, IPs should be currently active. An IP that was last seen a few months ago would have its priority decreased in our list.

Fifth, the number of bytes transferred and the number of packets sent and received will be greater.

All five of these traits need to be included in the sorting process of AIP and each of them needs to be weighted since they are not of equal importance. Therefore, there is a need to build a prioritization algorithm that receives data flows and outputs information built on top of these six characteristics.

Data Source

The program accepts a directory that contains data files from each day. You assign a directory for the program to look in every time it runs, and it checks if there are any new files to process. If there are, it processes the new files and remembers the names of the new files so that it does not process it the next time it runs.

In terms of file format, it accepts a .csv file that has one IP per line, with each of the following data inputs for each IP on that line, separated by commas:

Amount of events - Meaning the total connections to our honeypots originating from the given IP
Total Duration - How long did this IP connect for the total of its events
Average duration - The average length in seconds of all the connections per IP
Amount of Bytes - Total bytes sent and received
Average number of bytes - For bytes transferred in each connection per IP
Total packets - Of all the connections per IP
Average packets - Average packets sent per connection
Last event time - UNIX time of the last time the IP tried to connect to something in the last 24 hours
First event time - UNIX time of the first time the IP tried to connect in the last 24 hours

For example, a single line in the file could look like this:

"IPv4 Addrss",26049,"7415310","284.6","41808957","1605.0",284577,"10.92","157899154","1578968762.519"

The AIP Algorithm

The AIP algorithm takes each of the flows from the input and uses its data to calculate eight values for each IP. The first seven values from the input data remain unchanged, number of events, total duration, average duration, number of bytes, the average number of bytes, total packets and average packets. However, the first event time and the number of events are used to calculate the average number of events per day the IP has had since it was first seen by the program, giving us a total of eight features as input for our algorithm.

For each IP, each of the eight values is updated using the data from the current day and then saved to a file, called the absolute file. The absolute data file contains the values for all the IPs seen since the program was started.

The next step is to feed the absolute data file, which has been updated with the last 24 hours of events, into the rating program. The rating program assigns each of the eight values a specific weight. These weights control the effect each value will have on the final score. The sum of all weights is one.

Each feature is multiplied by its weight and then summed with the rest, as in a basic linear combination. Then the sum is multiplied by a time modifier. The program currently has three different modules each with its own time modifier, one prioritizing historically aggressive IPs, one prioritizing newer aggressive IPs and one only dealing with IPs seen in the last 24 hours.

Documentation

Click here to check some examples of how the tool is used and the data models.

About

The Attacker IP Prioritizer(AIP) algorithm is a python program designed to dynamically generate a resource-friendly IPv4 address blacklist based on data collected from attacks on a network.

Resources

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages