A Multi-resolution Port Scan Detection Technique for High-speed Networks

被引:0
|
作者
Moon, Hwashin [1 ]
Yi, Sungwon [2 ]
Choi, Gyu Sang [3 ]
Jeon, Yongsung [1 ]
Kim, Joengnyeo [1 ]
机构
[1] Elect & Telecommun Res Inst, Cyber Secur Res Div, Daejeon 34129, South Korea
[2] Elect & Telecommun Res Inst, Future Technol Res Div, Daejeon 34129, South Korea
[3] Yeungnam Univ, Dept Informat & Comp Engn, Gyoengsan 38541, South Korea
关键词
flow estimation; multi-resolution; port scan; MWSM; IDS; SYSTEM;
D O I
10.1688/JISE.2015.31.5.7
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In this paper, we present a novel failed flow dispersion estimation technique, called multi-window state map (MWSM), which requires a small amount of memory and a constant number of memory accesses for implementing the multi-resolution concept (e.g., MRDS). We then extended the proposed MWSM scheme into a complete port scan detector. The simulation results with real-world traffic traces indicate that the proposed estimation technique manages the expected relative error and average standard error of less than 0.8% and 9%, respectively, while limiting the memory consumption to less than 60% of MRDS. In addition, the number of false positives decreases by 61% compared to a scan detector based on MRDS when it is extended to a complete scan detector. Owing to its simple mechanism and architecture, the proposed technique is well suited to hardware implementation. Therefore, we believe that the proposed technique is practically viable in modern high-speed intrusion detection systems.
引用
收藏
页码:1613 / 1632
页数:20
相关论文
共 50 条
  • [1] A Modified Multi-Resolution Approach for Port Scan Detection
    Moon, Hwashin
    Yi, Sungwon
    Cho, Keeseong
    [J]. 2010 IEEE GLOBAL TELECOMMUNICATIONS CONFERENCE GLOBECOM 2010, 2010,
  • [2] DoS and Port Scan attack Detection in High Speed Networks
    Hasanifard, Masoud
    Ladani, Behrouz Tork
    [J]. 2014 11TH INTERNATIONAL ISC CONFERENCE ON INFORMATION SECURITY AND CRYPTOLOGY (ISCISC), 2014, : 61 - 66
  • [3] Multi-resolution community detection in massive networks
    Jihui Han
    Wei Li
    Weibing Deng
    [J]. Scientific Reports, 6
  • [4] Multi-resolution community detection in massive networks
    Han, Jihui
    Li, Wei
    Deng, Weibing
    [J]. SCIENTIFIC REPORTS, 2016, 6
  • [5] Scan Detection in High-Speed Networks Based on Optimal Dynamic Bit Sharing
    Li, Tao
    Chen, Shigang
    Luo, Wen
    Zhang, Ming
    [J]. 2011 PROCEEDINGS IEEE INFOCOM, 2011, : 3200 - 3208
  • [6] Multi-resolution neural networks for mammographic mass detection
    Spence, CD
    Sajda, P
    [J]. ADVANCES IN COMPUTER-ASSISTED RECOGNITION, 1999, 3584 : 259 - 265
  • [7] Towards Multi-layered Intrusion Detection in High-Speed Networks
    Golling, Mario
    Hofstede, Rick
    Koch, Robert
    [J]. 2014 6TH INTERNATIONAL CONFERENCE ON CYBER CONFLICT (CYCON 2014), 2014, : 191 - +
  • [8] Multi-resolution corner detection
    Pedersini, F
    Pozzoli, E
    Sarti, A
    Tubaro, S
    [J]. 2000 INTERNATIONAL CONFERENCE ON IMAGE PROCESSING, VOL III, PROCEEDINGS, 2000, : 881 - 884
  • [9] Speed-up keypoint mapping technique by multi-resolution and global information
    Qiao, Wei
    Li, Yong
    Jin, Hongbin
    Wen, Zhigang
    [J]. VISUAL INFORMATION PROCESSING AND COMMUNICATION VI, 2015, 9410
  • [10] Multi-resolution HDD contact detection technique for low SNR applications
    Daugela, Antanas
    Trantham, Jon D.
    Ryun, Scott E.
    Tadepalli, Srinivas
    [J]. MICROSYSTEM TECHNOLOGIES-MICRO-AND NANOSYSTEMS-INFORMATION STORAGE AND PROCESSING SYSTEMS, 2014, 20 (8-9): : 1597 - 1603