期刊文献+

基于流量统计特征的端口扫描检测算法 被引量:5

Port scan detection algorithms based on statistical traffic features
下载PDF
导出
摘要 根据网络流量的统计特征提出一种慢速端口扫描行为检测算法,以主机数和端口数的比值及被访问主机端口集合之间的相似度为基础,采用非参数累积和CUSUM算法及小波变换方法对流量统计特征进行分析,进而判断是否存在端口扫描行为。实验结果表明,所提取的网络流量特征及算法可以有效地检测异常行为,该方法和Snort相比较具有低的漏报率和误报率。 A slowly port scan detect method was presented based on the statistical traffic features. Two statistical features: the ratio between the number of hosts and ports a host communicates and similarities of the ports set, were selected to denote the traffic features. The CUSUM and wavelet transform methods were employed to analyze the features and detect the slowly port scan behaviors. The experimental results show that the methods proposed detect port scan behaviors efficiently and correctly, it has low false negative and false positive alarm rate compared with the Snort,
出处 《通信学报》 EI CSCD 北大核心 2007年第12期14-18,共5页 Journal on Communications
基金 国家自然科学基金资助项目(60574087) 国家高技术研究发展计划("863"计划)基金资助项目(2007AA01Z475 2007AA01Z480 2007AA01Z464) 国家"111引智计划"基金资助项目~~
关键词 流量分析 端口扫描 小波变换 CUSUM traffic analysis port scan wavelet transform CUSUM
  • 相关文献

参考文献4

  • 1ROESCH M, GREEN C. http://www.snort.org/docs/writing_rules/ chap2. html#tth_sEc2.4.2 [EB/OL].
  • 2JUNG J, PAXSON V, BERGER A W, et al. Fast portscan detection using sequential hypothesis testing[A]. Proc IEEE Symposium on Securry and Privacy 2004 [C]. Oakland, Canada, 2004. 211- 225.
  • 3STANIFORD S, HOAGLAND J A, MCALERNEY J M. Practical automated detection of stealthy portscans[J]. Journal of Computer Security, 2002, 10(1/2): 105-136.
  • 4LECKIE C, KOTAGIRI R. A probabilistic approach to detecting network scans[A]. Proceedings of the Eighth IEEE Network Operations and Management Symposium (NOMS 2002) [C]. Florence, Italy, 2002. 359-372.

同被引文献33

引证文献5

二级引证文献10

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部