DocumentCode :
837208
Title :
Impact of Packet Sampling on Portscan Detection
Author :
Mai, Jianning ; Sridharan, Ashwin ; Chuah, Chen-Nee ; Zang, Senior Mem Hui ; Ye, Tao
Author_Institution :
Dept. of Electr. & Comput. Eng., California Univ., Davis, CA
Volume :
24
Issue :
12
fYear :
2006
Firstpage :
2285
Lastpage :
2298
Abstract :
Packet sampling is commonly deployed in high-speed backbone routers to minimize resources used for network monitoring. It is known that packet sampling distorts traffic statistics and its impact has been extensively studied for traffic engineering metrics such as flow size and mean rate. However, it is unclear how packet sampling impacts anomaly detection, which has become increasingly critical to network providers. This paper is the first attempt to address this question by focusing on one common class of nonvolume-based anomalies, portscans, which are associated with worm/virus propagation. Existing portscan detection algorithms fall into two general approaches: target-specific and traffic profiling. We evaluated representative algorithms for each class, namely: 1) TRWSYN that performs stateful traffic analysis; 2) TAPS that tracks connection pattern of scanners; and 3) entropy-based traffic profiling. We applied these algorithms to detect portscans in both the original and sampled packet traces from a Tier-1 provider´s backbone network. Our results demonstrate that sampling introduces fundamental bias that degrades the effectiveness of these detection algorithms and dramatically increases false positives. Through both experiments and analysis, we identify the traffic features critical for anomaly detection that are affected by sampling. Finally, using insight gained from this study, we show how portscan algorithms can be enhanced to be more robust to sampling
Keywords :
entropy; sampling methods; telecommunication network routing; telecommunication security; telecommunication traffic; TAPS; TRWSYN; entropy-based traffic profiling; high-speed backbone router; network monitoring; packet sampling; portscan detection algorithm; target-specific; time access pattern scheme; traffic engineering; worm-virus propagation; Entropy-based profiling; portscan detection; sampling; threshold random walk (TRW); time access pattern scheme (TAPS);
fLanguage :
English
Journal_Title :
Selected Areas in Communications, IEEE Journal on
Publisher :
ieee
ISSN :
0733-8716
Type :
jour
DOI :
10.1109/JSAC.2006.884027
Filename :
4016145
Link To Document :
بازگشت