【24h】

A Hypothesis Testing Based Scalable TCP Scan Detection

机译:基于假设测试的可扩展TCP扫描检测

获取原文
获取原文并翻译 | 示例

摘要

The wide spread of worms, DDOS attacks and scan activities have greatly affected the network infrastructure security. For scan detection, traditionally most detection methods are flow based, thus undesirable for gigabits or multi-gigabits networks. To deal with this scalability problem, in this paper, a novel scan detection method is proposed, in which no flow record is required to maintain. Based on the observation that scans will generally generate a large volume of return RST packets, a hypothesis testing based approach is proposed. Experiments in practical network and on the DARPA 1998 datasets indicate that this algorithm is effective.
机译:蠕虫,DDOS攻击和扫描活动的广泛传播极大地影响了网络基础架构的安全性。对于扫描检测,传统上大多数检测方法都是基于流的,因此对于千兆位或数千兆位网络来说是不可取的。针对这种可扩展性问题,本文提出了一种无需维护流记录的新型扫描检测方法。基于扫描通常会产生大量返回RST数据包的观察,提出了一种基于假设检验的方法。在实际网络和DARPA 1998数据集上的实验表明,该算法是有效的。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号