期刊文献+

一种检测隐蔽扫描活动的模型

Model for Detecting Stealth-scan
下载PDF
导出
摘要 针对现有隐蔽扫描检测技术的不足,提出了一种基于网络流量特征的端口扫描检测模型,它采用与大多数现有检测技术不同的方式,在检测过程中不仅基于单个报文,而且结合基于会话的方式,在去除掉各种干扰检测的“噪声”扫描活动后,检测慢扫描、分布式扫描等异常隐蔽的扫描活动。实验表明,该检测模型对检测各种隐蔽扫描活动具有较高的准确率和较低的漏报率。 In view of existing stealth-scanning detection technology insufficiency, providing a new model based on characteristic of network's traffic for detecting stealth-scan, it adopts a different way from most existing detection techniques. It not only checks packet individually, but also combines the way based on conversation, and removes various kinds of "noise" activity of scanning that interference detection to go, Primary experiment indicates that this detection model has higher rute of accuracy and lower rate of false negatives to various stealth-scan.
出处 《计算机工程》 EI CAS CSCD 北大核心 2006年第24期144-145,151,共3页 Computer Engineering
关键词 端口扫描 噪声扫描 入侵检测 方差 Port scan Noise scan Intrusion detection Variance
  • 相关文献

参考文献8

  • 1Fyodor.The Art of Port Scanning[J].Phrack Magazine,1997,51(7):11-17.
  • 2Brenden C.Stealth Port Scanning Methods[EB/OL].http://www.giac.org/certified_professionals/practicals/gsec/1985.php.
  • 3唐小明,梁锦华,蒋建春,文伟平.网络端口扫描及其防御技术研究[J].计算机工程与设计,2002,23(9):15-17. 被引量:12
  • 4Ido D.PortSentry for Attack Detection[Z].2002-05-15.http://www.securityfocus.com/infocus/1580.
  • 5Marc Norton Snort[Z].http://www.snort.org.
  • 6Heberlein L T.Network Security Monitor(NSM)-Final Report[Z].1995.http://seclab.cs.ucdavis.edu/papers/NSM-final.pdf.
  • 7Staniford S,Hongland J,McAlerney J.SPICE:Practical Automated Detection of Stealthy Portscans[DB/OL].2002-04-15.http://www.silicondefense.com/pptntext/ Spice-JCS.pdf.
  • 8辛颖,徐敬东,肖建华.基于统计的异常检测引擎分析[J].计算机应用,2002,22(10):48-50. 被引量:6

二级参考文献4

  • 1[1]Fyodor.The Art of Scanning[EB/OL].Phrack 51 www. phrack. com
  • 2[2]CERT Advisory CA-96.21: TCP SYN Flooding and IP Spoofing Attacks. 24 September 1996.
  • 3[3]Phrack .Port Scanning without the SYN flag / Uriel Maimon. Phrack 49-15.
  • 4[4]Stuart Staniford, Jams A. Hoagland ,et al. Practical Automated.

共引文献15

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部