• DocumentCode
    1459938
  • Title

    A Network Activity Classification Schema and Its Application to Scan Detection

  • Author

    Treurniet, Joanne

  • Author_Institution
    Defence R&D Canada, Ottawa, ON, Canada
  • Volume
    19
  • Issue
    5
  • fYear
    2011
  • Firstpage
    1396
  • Lastpage
    1404
  • Abstract
    Internet traffic is neither well-behaved nor well-understood, which makes it difficult to detect malicious activities such as scanning. A large portion of scanning activity is of a slow scan type and is not currently detectable by security appliances. In this proof-of-concept study, a new scan detection technique is demonstrated that also improves our understanding of Internet traffic. Sessions are created using models of the behavior of packet-level data between host pairs, and activities are identified by grouping sessions based on patterns in the type of session, the IP addresses, and the ports. In a 24-h data set of nearly 10 million incoming sessions, a prodigious 78% were identified as scan probes. Of the scans, 80% were slower than basic detection methods can identify. To manage the large volume of scans, a prioritization method is introduced wherein scans are ranked based on whether a response was made and on the periodicity of the probes in the scan. The data is stored in an efficient manner, allowing activity information to be retained for very long periods of time. This technique provides insight into Internet traffic by classifying known activities, giving visibility to threats to the network through scan detection, while also extending awareness of the activities occurring on the network.
  • Keywords
    IP networks; Internet; security of data; telecommunication security; IP address; Internet traffic; activity information; malicious activity detection; network activity classification schema; packet-level data; periodicity; scan detection; scan probes; scanning activity; time 24 h; Backscatter; Computer crime; IP networks; Internet; Probes; Protocols; Sockets; Security and protection; system management; traffic analysis;
  • fLanguage
    English
  • Journal_Title
    Networking, IEEE/ACM Transactions on
  • Publisher
    ieee
  • ISSN
    1063-6692
  • Type

    jour

  • DOI
    10.1109/TNET.2011.2109009
  • Filename
    5720528