期刊文献+

一种新的端口扫描检测方法 被引量:2

An New Portscan Detection Method
下载PDF
导出
摘要 针对现有端口扫描方法存在的缺陷,提出一种端口扫描检测的新方法。该方法充分利用受保护网段内各主机的特征,对可疑事件进行关联分析,不但可以检测现有工具都可以检测的扫描,而且对慢速扫描的检测也非常有效。 A new portscan detection method is presented to overcome the existing defects of current portscan metrods. In this method, the hosts' features in the protected network are fully used to conduct the associate analysis to all the suspicious events. This method can detect all the scans that are detected by current techniques,and is quite efficient in slow scan detect.
出处 《广西科学院学报》 2005年第4期247-248,251,共3页 Journal of Guangxi Academy of Sciences
基金 广西留学回国人员科学基金(桂科回0342001) 广西科技攻关项目(桂科攻033008-9)联合资助
关键词 端口扫描 检测 慢速 异常值 分析器 portscan, detection, slow speed, abnormity value, analyzer
  • 相关文献

参考文献5

  • 1Stuart Staniford,James A Hoagland,Joseph MMcAlerney.Practical automated detection of stealthy portscans[J].Journal of Computer Security, 2002,10(1/2):105-136.
  • 2宋华,罗平,戴一奇.一种新的分布式端口扫描检测方法[J].计算机工程与应用,2003,39(8):163-166. 被引量:5
  • 3Caswell B,Beale J,Foster J C,et al.Snort 2.0 Intrusion Detection[M].Syngress publishing,2003.
  • 4Hyperion.Watcher Phrack Magazine.1998,53(8):11.
  • 5Ido Dubrawsky.PortSentry for Attack Detection[EB/OL].http://www.securityfocus.com/infocus/1580,2002-05.

二级参考文献8

  • 1[1]Fyodor. The Art of Scanning. Phrack Magazine 51
  • 2[2]Fyodor. Nmap 软件包.http://www.insecure.org/nmap/
  • 3[3]Fyodor. Remote OS detection via TCP/IP Stack Fingerprinting. PhrackMagazine 54
  • 4[4]PortSentry.Abacus 项目.http://www.psionic.com/abacus/portsentry/
  • 5[5]solar designer. Designing and Attacking Port Scan Detection Tools.Phrack Magazine 53
  • 6[6]Thamer AL-Herbish.synlog 软件包.http://www.whitefang.com/synlog.html
  • 7[7]Martin Roesch.Snort-Lightweight Intrusion Detection for Networks[C].In:USENIX Proceedings of LISA'99: 13th Systems AdministrationConference
  • 8[8]Stuart Staniford,James A Hoagland,Joseph M McAlemey. PracticalAutonated Detection of Stealthy Portscans[C].In:the 7th ACM Conference on Computer Security

共引文献4

同被引文献49

引证文献2

二级引证文献14

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部