期刊文献+

An Adaptive Algorithm to Detect Port Scans

An Adaptive Algorithm to Detect Port Scans
下载PDF
导出
摘要 Detection of port scan is an important component in a network intrusion detection and prevention system. Traditional statistical methods can be easily evaded by stealthy scans and are prone to DoS attacks. This paper presents a new mechanism termed PSD(port scan detection), which is based on TCP packet anomaly evaluation. By learning the port distribution and flags of TCP packets arriving at the protected hosts, PSD can compute the anomaly score of each packet and effectively detect port scans including slow scans and stealthy scans. Experiments show that PSD has high detection accuracy and low detection latency. Detection of port scan is an important component in a network intrusion detection and prevention system. Traditional statistical methods can be easily evaded by stealthy scans and are prone to DoS attacks. This paper presents a new mechanism termed PSD(port scan detection), which is based on TCP packet anomaly evaluation. By learning the port distribution and flags of TCP packets arriving at the protected hosts, PSD can compute the anomaly score of each packet and effectively detect port scans including slow scans and stealthy scans. Experiments show that PSD has high detection accuracy and low detection latency.
出处 《Journal of Shanghai University(English Edition)》 CAS 2004年第3期328-332,共5页 上海大学学报(英文版)
基金 ProjectsupportedbytheNationalHigh TechnologyResearchandDevelopmentProgramofChina(GrantNo .2 0 0 2AA14 5 0 90 )
关键词 port scan anomaly detection TCP/IP network security. port scan, anomaly detection, TCP/IP, network security.
  • 相关文献

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部