ISCAS OpenIR  > 信息安全国家重点实验室
an access-context based method to detect network scanning event in lan
Wu Di; Yin Ying; Chen Xiao-Hua; Bu Ning
2009
会议名称International Conference on Machine Learning and Cybernetics
会议录名称Proceedings of the 2009 International Conference on Machine Learning and Cybernetics
会议日期JUL 12-15,
会议地点Baoding, PEOPLES R CHINA
出版地345 E 47TH ST, NEW YORK, NY 10017 USA
出版者PROCEEDINGS OF 2009 INTERNATIONAL CONFERENCE ON MACHINE LEARNING AND CYBERNETICS, VOLS 1-6
ISBN978-1-4244-4705-3
部门归属Wu, Di Chinese Acad Sci, Inst Software, State Key Lab Informat Secur, Beijing 100080, Peoples R China.
摘要Usually there are leading DNS resolution operations in normal network access scenarios and at the same time the relative connection success ratio is very high; but there is no leading DNS resolution operation in network scanning scenarios and the relative connection success ratio is very low. For convenience in this paper we named the network access connection attempt without leading DNS resolution operation as Suspicious Network Access (SNA). A network scanning detection approach is proposed in this paper by the analysis of SNAs response ratio and the randomness of their target IP addresses for each host in LAN. Since the proposed approach only takes the SNAs into account and the interference from normal network access can be decreased effectively, it can detect network scanning attacks with high accuracy and efficiency. The experiment results in simulation network scenario showed that the proposed approach support the detection of TCP-SYN and ICMP type network scanning attacks and also support the detection of stealth network scanning attacks as well.
关键词Network Security Network Monitoring Network Scanning Intrusion Detection
主办者Hebei Univ, IEEE Syst, Man & Cybernet Soc, Chongqing Univ, S China Univ Technol, Honk Kong Baptist Univ, Hebei Univ Sci & Technol
内容类型会议论文
URI标识http://ir.iscas.ac.cn/handle/311060/8200
专题信息安全国家重点实验室
推荐引用方式
GB/T 7714
Wu Di,Yin Ying,Chen Xiao-Hua,et al. an access-context based method to detect network scanning event in lan[C]. 345 E 47TH ST, NEW YORK, NY 10017 USA:PROCEEDINGS OF 2009 INTERNATIONAL CONFERENCE ON MACHINE LEARNING AND CYBERNETICS, VOLS 1-6,2009.
条目包含的文件
条目无相关文件。
个性服务
推荐该条目
保存到收藏夹
查看访问统计
导出为Endnote文件
谷歌学术
谷歌学术中相似的文章
[Wu Di]的文章
[Yin Ying]的文章
[Chen Xiao-Hua]的文章
百度学术
百度学术中相似的文章
[Wu Di]的文章
[Yin Ying]的文章
[Chen Xiao-Hua]的文章
必应学术
必应学术中相似的文章
[Wu Di]的文章
[Yin Ying]的文章
[Chen Xiao-Hua]的文章
相关权益政策
暂无数据
收藏/分享
所有评论 (0)
暂无评论
 

除非特别说明,本系统中所有内容都受版权保护,并保留所有权利。