Connectionless port scan detection on the backbone

被引:6
|
作者
Sridharan, Avinash [1 ]
Ye, Tao [2 ]
Bhattacharyya, Supratik [2 ]
机构
[1] Univ So Calif, Dept Elect Engn, Los Angeles, CA 90089 USA
[2] Sprint ATL, Burlingame, CA USA
关键词
D O I
10.1109/.2006.1629454
中图分类号
TN [电子技术、通信技术];
学科分类号
0809 ;
摘要
Considerable research has been done on detecting and blocking portscan activities that are typically conducted by infected hosts to discover other vulnerable hosts. However, the focus has been on enterprise gateway-level Intrusion Detection Systems where the traffic volume is low and network configuration information is readily available. This paper investigates the effectiveness of existing portscan detection algorithms in the context of a large transit backbone network and proposes a new algorithm that meets the demands of aggregated high speed backbone traffic. Specifically, we evaluate two existing approaches - the portscan detection algorithm in SNORT [8], and a modified version of the TRW algorithm [6) that is a part of the intrusion detection tool BRO [12]. We then propose a new approach, TAPS, which uses sequential hypothesis testing to detect hosts that exhibit abnormal access patterns in terms of destination hosts and destination ports. We perform a comparative analysis of these three approaches using real backbone packet traces, and find that TAPS exhibits the best performance in terms of catching the maximum number of true scanners and yielding the least number of false positives. We have a working implementation of TAPS on our monitoring platform. Further implementation optimizations using bloom filters are identified and discussed.
引用
收藏
页码:567 / +
页数:4
相关论文
共 50 条
  • [1] Port Scan Detection
    Gadge, Jayant
    Patil, Anish Anand
    [J]. PROCEEDINGS OF THE 2008 16TH INTERNATIONAL CONFERENCE ON NETWORKS, 2008, : 350 - 355
  • [2] A Novel Approach to Scan Detection on the Backbone
    Zhang, Yu
    Fang, Binxing
    [J]. PROCEEDINGS OF THE 2009 SIXTH INTERNATIONAL CONFERENCE ON INFORMATION TECHNOLOGY: NEW GENERATIONS, VOLS 1-3, 2009, : 16 - +
  • [3] Interactive visualization for network and port scan detection
    Muelder, C
    Ma, KL
    Bartoletti, T
    [J]. RECENT ADVANCES IN INTRUSION DETECTION, 2006, 3858 : 265 - 283
  • [4] A Study on Risk Index to Analyze the Impact of Port Scan and to Detect Slow Port Scan in Network Intrusion Detection
    Park, Seongchul
    Kim, Juntae
    [J]. ADVANCED SCIENCE LETTERS, 2017, 23 (10) : 10329 - 10336
  • [5] Scalable Double Filter Structure for Port Scan Detection
    Kong, Shijin
    He, Tao
    Shao, Xiaoxin
    An, Changqing
    Li, Xing
    [J]. 2006 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS, VOLS 1-12, 2006, : 2177 - 2182
  • [6] Spark-Based Port and Net Scan Detection
    Affinito, Antonia
    Botta, Alessio
    Gallo, Luigi
    Garofalo, Mauro
    Ventre, Giorgio
    [J]. PROCEEDINGS OF THE 35TH ANNUAL ACM SYMPOSIUM ON APPLIED COMPUTING (SAC'20), 2020, : 1172 - 1179
  • [7] Feasibility Study of Port Scan Detection on Encrypted Data
    Chandrashekar, Prakruti
    Dara, Sashank
    Muralidhara, V. N.
    [J]. 2015 IEEE INTERNATIONAL CONFERENCE ON CLOUD COMPUTING IN EMERGING MARKETS (CCEM), 2016, : 109 - 112
  • [8] A Modified Multi-Resolution Approach for Port Scan Detection
    Moon, Hwashin
    Yi, Sungwon
    Cho, Keeseong
    [J]. 2010 IEEE GLOBAL TELECOMMUNICATIONS CONFERENCE GLOBECOM 2010, 2010,
  • [9] DoS and Port Scan attack Detection in High Speed Networks
    Hasanifard, Masoud
    Ladani, Behrouz Tork
    [J]. 2014 11TH INTERNATIONAL ISC CONFERENCE ON INFORMATION SECURITY AND CRYPTOLOGY (ISCISC), 2014, : 61 - 66
  • [10] A Profile-Based Fast Port Scan Detection Method
    Hajdu-Szucs, Katalin
    Laki, Sandor
    Kiss, Attila
    [J]. COMPUTATIONAL COLLECTIVE INTELLIGENCE, ICCCI 2017, PT I, 2017, 10448 : 401 - 410