A Study on Risk Index to Analyze the Impact of Port Scan and to Detect Slow Port Scan in Network Intrusion Detection

被引:3
|
作者
Park, Seongchul [1 ]
Kim, Juntae [1 ]
机构
[1] Dongguk Univ, Dept Comp Engn, Seoul, South Korea
基金
新加坡国家研究基金会;
关键词
Network Port Scan; Stealth Port Scan; Slow Port Scan; Network Intrusion Detection System; Risk Index; Principal Component Analysis;
D O I
10.1166/asl.2017.10446
中图分类号
O [数理科学和化学]; P [天文学、地球科学]; Q [生物科学]; N [自然科学总论];
学科分类号
07 ; 0710 ; 09 ;
摘要
Network port scan attack is a tool with which to identify any opened port in a system within the internal network. In most existing instances of the intrusion detection system, the port scan attack has been considered 'executed' against the source IP address for the outgoing packets whose count is higher than the threshold set according to the record of packets sent to the system or network per unit of time. That is, the risk level of a source IP address performing the network port scan attack has relied on the count of port scan attacks recorded by IDSs. However, the risk measurement solely based on the count of port scan attacks yields low port scan detection rates for the increased false negatives on slow port scan attacks. In this study, four different forms of the information are highlighted to accurately and comprehensively identify the network port scan attacks. A risk index quantifying such information through the Principal Component Analysis (PCA) is hereby proposed to express integrated risks on the port scan attacks. The detection using the risk index proposed through the experimentation demonstrates superior port scan detection rates than Snort.
引用
收藏
页码:10329 / 10336
页数:8
相关论文
共 38 条
  • [1] Port Scan Detection
    Gadge, Jayant
    Patil, Anish Anand
    [J]. PROCEEDINGS OF THE 2008 16TH INTERNATIONAL CONFERENCE ON NETWORKS, 2008, : 350 - 355
  • [2] Interactive visualization for network and port scan detection
    Muelder, C
    Ma, KL
    Bartoletti, T
    [J]. RECENT ADVANCES IN INTRUSION DETECTION, 2006, 3858 : 265 - 283
  • [3] Rule-Based Network Intrusion Detection System for Port Scanning with Efficient Port Scan Detection Rules Using Snort
    Patel, Satyendra Kumar
    Sonker, Abhilash
    [J]. INTERNATIONAL JOURNAL OF FUTURE GENERATION COMMUNICATION AND NETWORKING, 2016, 9 (06): : 339 - 350
  • [4] Connectionless port scan detection on the backbone
    Sridharan, Avinash
    Ye, Tao
    Bhattacharyya, Supratik
    [J]. 2006 IEEE INTERNATIONAL PERFORMANCE COMPUTING AND COMMUNICATIONS CONFERENCE, VOLS 1 AND 2, 2006, : 567 - +
  • [5] Feasibility Study of Port Scan Detection on Encrypted Data
    Chandrashekar, Prakruti
    Dara, Sashank
    Muralidhara, V. N.
    [J]. 2015 IEEE INTERNATIONAL CONFERENCE ON CLOUD COMPUTING IN EMERGING MARKETS (CCEM), 2016, : 109 - 112
  • [6] Analysis of Intrusion Detection System Performance for the Port Scan Attack Detector, Portsentry, and Suricata
    Ernawati, T.
    Fachrozi, M. F.
    Syaputri, D. D.
    [J]. 2ND INTERNATIONAL CONFERENCE ON INFORMATICS, ENGINEERING, SCIENCE, AND TECHNOLOGY (INCITEST 2019), 2019, 662
  • [7] Alternative Engine to Detect and Block Port Scan Attacks using Virtual Network Environments
    Fuertes, Walter
    Zambranonandh, Patricio
    Sanchez, Marco
    Gamboa, Pablo
    [J]. INTERNATIONAL JOURNAL OF COMPUTER SCIENCE AND NETWORK SECURITY, 2011, 11 (11): : 14 - 23
  • [8] Detecting Slow Port Scan Using Fuzzy Rule Interpolation
    Almseidin, Mohammad
    Al-kasassbeh, Mouhammd
    Kovacs, Szilveszter
    [J]. 2019 2ND INTERNATIONAL CONFERENCE ON NEW TRENDS IN COMPUTING SCIENCES (ICTCS), 2019, : 33 - 38
  • [9] A New Method about Port Scan of Network hosts
    Han, Xinchao
    Ma, Yongqiang
    [J]. MATERIALS ENGINEERING FOR ADVANCED TECHNOLOGIES, PTS 1 AND 2, 2011, 480-481 : 190 - +
  • [10] Using Quadratic Discriminant Analysis by Intrusion Detection Systems for Port Scan and Slowloris Attack Classification
    Deolindo, Vinicius M.
    Dalmazo, Bruno L.
    da Silva, Marcus V. B.
    de Oliveira, Luiz R. B.
    Silva, Allan de B.
    Granville, Lisandro Zambenedetti
    Gaspary, Luciano P.
    Nobre, Jeferson Campos
    [J]. COMPUTATIONAL SCIENCE AND ITS APPLICATIONS, ICCSA 2021, PT III, 2021, 12951 : 188 - 200