Detection of slow port scans in flow-based network traffic

被引:24
|
作者
Ring, Markus [1 ]
Landes, Dieter [1 ]
Hotho, Andreas [2 ]
机构
[1] Coburg Univ Appl Sci & Arts, Fac Elect Engn & Informat, D-96450 Coburg, Germany
[2] Univ Wurzburg, Data Min & Informat Retrieval Grp, D-97074 Wurzburg, Germany
来源
PLOS ONE | 2018年 / 13卷 / 09期
关键词
D O I
10.1371/journal.pone.0204507
中图分类号
O [数理科学和化学]; P [天文学、地球科学]; Q [生物科学]; N [自然科学总论];
学科分类号
07 ; 0710 ; 09 ;
摘要
Frequently, port scans are early indicators of more serious attacks. Unfortunately, the detection of slow port scans in company networks is challenging due to the massive amount of network data. This paper proposes an innovative approach for preprocessing flow-based data which is specifically tailored to the detection of slow port scans. The preprocessing chain generates new objects based on flow-based data aggregated over time windows while taking domain knowledge as well as additional knowledge about the network structure into account. The computed objects are used as input for the further analysis. Based on these objects, we propose two different approaches for detection of slow port scans. One approach is unsupervised and uses sequential hypothesis testing whereas the other approach is supervised and uses classification algorithms. We compare both approaches with existing port scan detection algorithms on the flow-based CIDDS-001 data set. Experiments indicate that the proposed approaches achieve better detection rates and exhibit less false alarms than similar algorithms.
引用
收藏
页数:18
相关论文
共 50 条
  • [1] A flow-based method for abnormal network traffic detection
    Kim, MS
    Kang, HJ
    Hong, SC
    Chung, SH
    Hong, JW
    NOMS 2004: IEEE/IFIP NETWORK OPERATIONS AND MANAGMENT SYMPOSIUM: MANAGING NEXT GENERATION CONVERGENCE NETWORKS AND SERVICES, 2004, : 599 - 612
  • [2] Intrusion Detection Using Flow-Based Analysis of Network Traffic
    David, Jisa
    Thomas, Ciza
    ADVANCES IN NETWORKS AND COMMUNICATIONS, PT II, 2011, 132 : 391 - 399
  • [3] Scalable network architecture for flow-based traffic control
    Song, Jongtae
    Lee, Soon Seok
    Kang, Kug-Chang
    Park, Noik
    Park, Heuk
    Ybon, Sunghyun
    Chun, Kyung Gyu
    Chang, Mi Young
    Joung, Jinoo
    Kim, Young Sun
    ETRI JOURNAL, 2008, 30 (02) : 205 - 215
  • [4] Network Traffic Characterisation Using Flow-Based Statistics
    Velan, Peter
    Medkova, Jana
    Jirsik, Tomas
    Celeda, Pave
    NOMS 2016 - 2016 IEEE/IFIP NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM, 2016, : 907 - 912
  • [5] FlowOS: A Pure Flow-based Vision of Network Traffic
    Alim, Abdul
    Bezahaf, Mehdi
    Mathy, Laurent
    PROCEEDINGS OF THE EIGHTH ACM/IEEE SYMPOSIUM ON ARCHITECTURES FOR NETWORKING AND COMMUNICATIONS SYSTEMS (ANCS'12), 2012, : 143 - 144
  • [6] DDoS Attack Detection using Fast Entropy Approach on Flow-Based Network Traffic
    David, Jisa
    Thomas, Ciza
    BIG DATA, CLOUD AND COMPUTING CHALLENGES, 2015, 50 : 30 - 36
  • [7] Efficient DDoS flood attack detection using dynamic thresholding on flow-based network traffic
    David, Jisa
    Thomas, Ciza
    COMPUTERS & SECURITY, 2019, 82 : 284 - 295
  • [8] DeepGFL: Deep Feature Learning via Graph for Attack Detection on Flow-based Network Traffic
    Yao, Yepeng
    Su, Liya
    Lu, Zhigang
    2018 IEEE MILITARY COMMUNICATIONS CONFERENCE (MILCOM 2018), 2018, : 579 - 584
  • [9] IMS Network Deployment Cost Optimization Based on Flow-Based Traffic Model
    Xiao, Jie
    Huang, Changcheng
    Yan, James
    PROCEEDINGS OF THE 2010 IEEE-IFIP NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM, 2010, : 232 - 239
  • [10] NTCS: A Real Time Flow-based Network Traffic Classification System
    Lopes Pereira, Silas Santiago
    de Castro e Silva, Jorge Luiz
    Bessa Maia, Jose Everardo
    2014 10TH INTERNATIONAL CONFERENCE ON NETWORK AND SERVICE MANAGEMENT (CNSM), 2014, : 368 - 371