期刊文献+

一种新的分布式端口扫描检测方法 被引量:5

A New Distributed Portscan_Detection Method
下载PDF
导出
摘要 文章介绍了各种扫描技术,总结了已有的检测方法。在此基础上,文章提出了一种新的分布式的端口扫描检测方法。检测的传感器部分实现对异常包的检测,分析器部分通过将异常包分成不同的类,计算一个类的异常值的总和,然后判断出扫描。这种方法不仅可以检测出现有的各种扫描工具能够检测出的扫描,也能检测出它们不能检测出的扫描,例如分布式扫描,慢速扫描等等。 This paper introduces many of the portscan techniques,and discusses the detection tools in the real world.Then it presents a new distributed portscan detection method.The sensor detects the anomalous packets.The Analyzer groups the anomalous packets into different classes,calculates the class's anomaly sum value,and then judges if that is a scan.This method can detect not only all the scans that are detected by current techniques,but also slow scans and distributed scans that can't be detected by now.
出处 《计算机工程与应用》 CSCD 北大核心 2003年第8期163-166,共4页 Computer Engineering and Applications
关键词 端口扫描 分布式扫描 端口扫描检测 分布式端口扫描检测 Portscan,Distributed scan,Portscan detection,Distributed portscan detection
  • 相关文献

参考文献8

  • 1[1]Fyodor. The Art of Scanning. Phrack Magazine 51
  • 2[2]Fyodor. Nmap 软件包.http://www.insecure.org/nmap/
  • 3[3]Fyodor. Remote OS detection via TCP/IP Stack Fingerprinting. PhrackMagazine 54
  • 4[4]PortSentry.Abacus 项目.http://www.psionic.com/abacus/portsentry/
  • 5[5]solar designer. Designing and Attacking Port Scan Detection Tools.Phrack Magazine 53
  • 6[6]Thamer AL-Herbish.synlog 软件包.http://www.whitefang.com/synlog.html
  • 7[7]Martin Roesch.Snort-Lightweight Intrusion Detection for Networks[C].In:USENIX Proceedings of LISA'99: 13th Systems AdministrationConference
  • 8[8]Stuart Staniford,James A Hoagland,Joseph M McAlemey. PracticalAutonated Detection of Stealthy Portscans[C].In:the 7th ACM Conference on Computer Security

同被引文献29

引证文献5

二级引证文献11

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部