Anti Honeypot Technology 289
However, some time must be allowed between sending the
packets and checking the reports. Participants in the ISC network
typically submit logs every hour, and additional time should be
allowed in case some participants take a little longer, perhaps for
a total wait of two hours. Obviously, at this rate it will take far too
long to check every IP address one by one. In order for a sensor
probing attack to be feasible, many addresses need to be tested at
the same time.
Two observations will help us accomplish this. First, the vast
majority of IP addresses either do not correspond to any host,
or correspond to one that is not submitting logs. With relatively
few monitored addresses, there will necessarily be large ...