期刊文献+

扫描检测平台效用评估 被引量:1

Effectiveness Evaluation of a Scan Detection Platform
下载PDF
导出
摘要 利用网络中未使用IP地址构建扫描检测平台能够有效提高检测准确率,降低虚警率.在扫描检测平台实际构建之前,需要对可控部署地址资源的预计检测效用进行评估,以确定地址资源可达的检测目标以及明确平台构建的必要性.为此,提出一种基于网络分类的扫描检测模型,依据此模型可对扫描检测平台对于随机扫描源和本地优先扫描源的检测效用进行评估,为扫描检测平台部署构建提供理论指导.以法国电信Leurre’com Honeynet Project实际分布式检测平台作为效用评估样例.评估结果表明该检测平台能够有效检测类似Slammer蠕虫的高速随机扫描源和每秒至少发出2个扫描连接的本地优先扫描源,对低速扫描源检测效用低下.实际数据统计结果与仿真实验验证了评估结果的准确性. A scan detection phtform constructed by unused IP addresses will effectively improve detection accuracy and reduce false alarm. Before constructing a real scan detection phfform, we need to evaluate the detection effectiveness of controlled monitoring addresses to predict the detecting tagets and determine the necessity of the phfform deployment. To match these requirements, a new scan detection model based on network classification is presented. According to this model, we can evaluate the detection effectiveness of a scan detection phfform which is used to detect random or local preference scanning sources and provide theory guidance for the phtform construction and deployment. We use the Leurre' com Honeynet Project's distributed scan detection phfform as a practical evaluation instance. Evaluation resttlts show that the phtform can effectively detect high speed random scanning sources like Slammer worm and local preference scanning sources whose average scanning rate is more than 2 scan connections per second. To low speed scanning sources, the detection effectiveness is poor. Statistics of real monitoring data and simttlation resttlts validate the veracity of evaluation resttlts.
出处 《厦门大学学报(自然科学版)》 CAS CSCD 北大核心 2007年第A02期79-83,共5页 Journal of Xiamen University:Natural Science
关键词 扫描检测 扫描检测平台 扫描检测模型 效用评估 scan detection scan detection platform scan detection model effectiveness evaluation
  • 相关文献

参考文献8

  • 1Moore D. Network telescopes: observing small or distant security events[R]. In: 11th USENIX Security Symposium, Invited Talk, 2002.
  • 2Bailey M, Cooke E, Jahanian F, et al. The internet motion sensor-distributed blackhole monitoring system [C]// In:Proc. of the ISOC Network and Distributed Systems Security Symposium. 2005.
  • 3leurrecom, org Honeypot project[EB/OL]. ( 2003-06-01 ) [ 2007-05-15 ] http ://www. leurrecom.org.
  • 4Honeynet Project. [ EB/OL]. (2003-03424) [ 2007-05- 15 ] http ://www. honeynet.org.
  • 5Rajab M A, Monrose, F, Terzis A. On the effectiveness of distributed worm monitoring[ C]// In: Proc. of the 14th USENIX Security Symposium. 2005 : 225 - 237.
  • 6Moore D, Paxson V, Savage S, et al. Inside the Slammer worm[J]. IEEE Magazine on Security and Privacy, 2003,1 (4) : 33 -39.
  • 7eEye digital security: . ida "Code Red" worm [ EB/OL]. (2001-07-17) [2007-05-15] http://www.eeye. com/html/Research/Advisories/AL20010717.html.
  • 8RFC3194. The Host-Density Ratio for Address Assignment Efficiency: An update on the H ratio [EB/OL]. (2001-11- 01 ) [ 2007-04-16] http://www.rfc-editor.org/rfc/rfc3194.txt.

同被引文献6

引证文献1

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部