...
首页> 外文期刊>International journal of secure software engineering >Improving the Detection of On-Line Vertical Port Scan in IP Traffic
【24h】

Improving the Detection of On-Line Vertical Port Scan in IP Traffic

机译:改善IP流量中在线垂直端口扫描的检测

获取原文
获取原文并翻译 | 示例
           

摘要

The authors propose in this paper an on-line algorithm based on Bloom filters to detect port scan attacks in IP traffic. Only relevant information about destination IP addresses and destination ports are stored in two steps in a two-dimensional Bloom filter. This algorithm can be indefinitely performed on a real traffic stream thanks to a new adaptive refreshing scheme that closely follows traffic variations. It is a scalable algorithm able to deal with IP traffic at a very high bit rate thanks to the use of hashing functions over a sliding window. Moreover it does not need any a priori knowledge about traffic characteristics. When tested against real IP traffic, the proposed on-line algorithm performs well in the sense that it detects all the port scan attacks within a very short response time of only 10 seconds without any false positive.
机译:作者在本文中提出了一种基于Bloom过滤器的在线算法来检测IP流量中的端口扫描攻击。在二维布隆过滤器中,只有有关目标IP地址和目标端口的相关信息才分两步存储。得益于紧随流量变化的新型自适应刷新方案,该算法可以无限期地在实际流量上执行。由于在滑动窗口上使用了哈希函数,它是一种可扩展的算法,能够以很高的比特率处理IP流量。此外,它不需要有关交通特征的任何先验知识。当针对实际IP流量进行测试时,建议的在线算法在以下方面表现良好:它可以在仅10秒的非常短的响应时间内检测到所有端口扫描攻击,而不会出现误报。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号