Title :
A Novel Approach to Scan Detection on the Backbone
Author :
Zhang, Yu ; Fang, Binxing
Author_Institution :
Res. Center of Comput. Network & Inf. Security Technol., Harbin Inst. of Technol., Harbin
Abstract :
Scanning activities are usually conducted by infected hosts to discover other vulnerable hosts or by a motivated adversary to gather information, and are typically precursor to most of the cyber attacks. There are many scan detection approaches at present; however, most of them focus on enterprise-level network where the traffic volume is low, bi-directional and packet-level information are available. This paper proposes a new port scan detection approach-time based flow size distribution sequential hypothesis testing or TFDS briefly, for high-speed transit network where only unidirectional flow information is available. TFDS uses the main idea of sequential hypothesis testing to detect scanners that exhibit abnormal access patterns in terms of flow size distribution (FSD) entropy. We make a comparison with the state-of-the-art backbone port scan detection method TAPS in terms of efficiency and effectiveness using real backbone packet trace, and find that TFDS performs much better than TAPS.
Keywords :
IP networks; entropy; telecommunication security; IP backbone monitoring; cyber attack; flow size distribution entropy; high-speed transit network; real backbone packet trace; real time port scan detection; sequential hypothesis testing; time based flow size distribution; unidirectional flow information; Bidirectional control; Detectors; Entropy; Information security; Labeling; Payloads; Sequential analysis; Spine; Statistics; Telecommunication traffic; Flow size distribution entropy; IP backbone monitoring; Port scanning; Real time port scan detection; Sequential hypothesis testing;
Conference_Titel :
Information Technology: New Generations, 2009. ITNG '09. Sixth International Conference on
Conference_Location :
Las Vegas, NV
Print_ISBN :
978-1-4244-3770-2
Electronic_ISBN :
978-0-7695-3596-8
DOI :
10.1109/ITNG.2009.16