Search arXivSearch

arXiv · 2510.25050

Merit Network Telescope: Processing and Initial Insights from Nearly 20 Years of Darknet Traffic for Cybersecurity Research

Abstract

This paper presents an initial longitudinal analysis of unsolicited Internet traffic collected between 2005 and 2025 by one of the largest and most persistent network telescopes in the United States, operated by Merit Network. The dataset provides a unique view into global threat activity as observed through scanning and backscatter traffic, key indicators of large-scale probing behavior, data outages, and ongoing denial-of-service (DoS) campaigns. To process this extensive archive, coarse-to-fine methodology is adopted in which general insights are first extracted through a resource-efficient metadata sub-pipeline, followed by a more detailed packet header sub-pipeline for finer-grained analysis. The methodology establishes two sub-pipelines to enable scalable processing of nearly two decades of telescope data and supports multi-level exploration of traffic dynamics. Initial insights highlight long-term trends and recurring traffic spikes, some attributable to Internet-wide scanning events and others likely linked to DoS activities.We present general observations spanning 2006-2024, with a focused analysis of traffic characteristics during 2024.

Explore related subjects

Keep this discovery

Explore connections, maps & timelines

BibTeXRIS

Shereen Ismail, Eman Hammad, William Hatcher, Salah Dandan, Ammar Alomari, Michael Spratt. 2025-10-29. Merit Network Telescope: Processing and Initial Insights from Nearly 20 Years of Darknet Traffic for Cybersecurity Research. https://arxiv.org/abs/2510.25050

Cite the original work for its findings. Save a collection to share your selection of sources.

KEEP EXPLORING

Related papers

The Benefit of Collective Intelligence in Community-Based Content Moderation is Limited by Overt Political Signalling

Social media platforms face increasing scrutiny over the rapid spread of misinformation. In response, many have adopted community-based content moderation systems, including Community Notes (formerly Birdwatch) on X (formerly Twitter), Community Notes on Meta, and Footnotes on TikTok. However, research shows that the current design of these systems can allow political biases to influence both the development of notes and the rating processes, reducing their overall effectiveness. We hypothesise that enabling users to collaborate on writing notes, rather than relying solely on individually authored notes, can enhance the overall quality of their notes. To test this idea, we conducted an online experiment in which participants jointly authored notes on politically misleading posts. We find that collaboration improves the helpfulness of notes, although the average effect depends on the interactional context. In particular, the benefits of collaboration decline when participants are made aware of one another's political affiliations. We also find that politically diverse teams improve note quality when evaluating Republican posts, while team composition does not meaningfully affect note quality for Democrat posts. These findings underscore the complexity of community-based content moderation and highlight the importance of understanding group dynamics and political diversity when designing more effective moderation systems.

cs.SI

The Same Ledger, Different Verdicts: How Measurement Specification Determines On-Chain Concentration

Whether a public blockchain is "decentralized" is routinely settled by citing a concentration statistic. On two ERC-20 ledgers, Chainlink (LINK) and Uniswap (UNI) over a 90-day window, we show that verdict depends on measurement specification rather than the ledger itself. Four discretionary choices (holder population, address type, temporal aggregation, and entity resolution) move the balance HHI for UNI from 109 to 2,336 (a factor of 21), with every specification defensible. Over the same range, the Gini coefficient moves by less than 0.003 and does not change under entity resolution, demonstrating that Gini and HHI answer different questions and cannot substitute for one another. We further document an implementation choice - summing versus overwriting repeated transfers - that discards roughly 85% of volume and overturns a finding on wealth and structural position. Substantively, both ledgers are extraordinarily unequal in ownership (balance Gini = 0.990 and 0.998) yet unconcentrated in routing (weekly flow HHI = 421 and 386), with the two dimensions close to statistically independent across addresses. A parameterized criterion for hidden brokers identifies 30 and 18 zero-balance intermediaries, 12 shared across ledgers; a matched control confirms that degree thresholding, rather than learned embeddings, drives the discovery. Finally, on the governance ledger, proposal-eligible addresses and routing intermediaries are almost disjoint, so routing contestability is held at the pleasure of a rule layer with a Nakamoto coefficient of two. We conclude that on-chain concentration should be reported as a specified range rather than a point estimate.

cs.SI

Optimal and heuristic strategies for evaluating the influence of coordinated behavior in information cascades and retweet networks

Coordinated Inauthentic Behavior (CIB) has become a major concern in online social platforms, yet its actual impact on information diffusion remains poorly understood. Existing research has primarily focused on detecting coordinated activity, while comparatively little attention has been devoted to quantifying its influence once detected. In this work, we introduce two complementary frameworks for the post-hoc evaluation of coordinated accounts. First, we formulate the problem on information cascades as a constrained influence maximization problem over directed trees and develop a polynomial-time dynamic programming algorithm that computes the optimal placement of coordinated nodes, providing an upper bound on their achievable influence. Second, motivated by the limited availability of diffusion cascades in real-world platforms, we propose a network-based framework that estimates influence directly from retweet networks using the independent cascade model and compares the observed placement of coordinated accounts against established heuristic baselines. We evaluate both approaches on Twitter/X data from the 2019 UK General Election and on a collection of verified state-backed information operation campaigns spanning multiple countries. While coordinated accounts exhibit limited influence in the UK cascades, the network-based analysis reveals substantial differences across campaigns, with several operations achieving influence comparable to or exceeding that of structurally central seed sets. Finally, by reconstructing cascades from the retweet networks, we show that the two frameworks produce consistent results, suggesting that the observed effects reflect intrinsic structural properties of coordinated activity rather than artifacts of the underlying methodology.

cs.SI