ISCAS OpenIR  > 信息安全国家重点实验室
an access-context based method to detect network scanning event in lan
Wu Di; Yin Ying; Chen Xiao-Hua; Bu Ning
2009
Conference NameInternational Conference on Machine Learning and Cybernetics
SourceProceedings of the 2009 International Conference on Machine Learning and Cybernetics
Conference DateJUL 12-15,
Conference PlaceBaoding, PEOPLES R CHINA
Publish Place345 E 47TH ST, NEW YORK, NY 10017 USA
PublisherPROCEEDINGS OF 2009 INTERNATIONAL CONFERENCE ON MACHINE LEARNING AND CYBERNETICS, VOLS 1-6
ISBN978-1-4244-4705-3
DepartmentWu, Di Chinese Acad Sci, Inst Software, State Key Lab Informat Secur, Beijing 100080, Peoples R China.
English AbstractUsually there are leading DNS resolution operations in normal network access scenarios and at the same time the relative connection success ratio is very high; but there is no leading DNS resolution operation in network scanning scenarios and the relative connection success ratio is very low. For convenience in this paper we named the network access connection attempt without leading DNS resolution operation as Suspicious Network Access (SNA). A network scanning detection approach is proposed in this paper by the analysis of SNAs response ratio and the randomness of their target IP addresses for each host in LAN. Since the proposed approach only takes the SNAs into account and the interference from normal network access can be decreased effectively, it can detect network scanning attacks with high accuracy and efficiency. The experiment results in simulation network scenario showed that the proposed approach support the detection of TCP-SYN and ICMP type network scanning attacks and also support the detection of stealth network scanning attacks as well.
KeywordNetwork Security Network Monitoring Network Scanning Intrusion Detection
SponsorshipHebei Univ, IEEE Syst, Man & Cybernet Soc, Chongqing Univ, S China Univ Technol, Honk Kong Baptist Univ, Hebei Univ Sci & Technol
Content Type会议论文
URIhttp://ir.iscas.ac.cn/handle/311060/8200
Collection信息安全国家重点实验室
Recommended Citation
GB/T 7714
Wu Di,Yin Ying,Chen Xiao-Hua,et al. an access-context based method to detect network scanning event in lan[C]. 345 E 47TH ST, NEW YORK, NY 10017 USA:PROCEEDINGS OF 2009 INTERNATIONAL CONFERENCE ON MACHINE LEARNING AND CYBERNETICS, VOLS 1-6,2009.
Files in This Item:
There are no files associated with this item.
Related Services
Recommend this item
Bookmark
Usage statistics
Export to Endnote
Google Scholar
Similar articles in Google Scholar
[Wu Di]'s Articles
[Yin Ying]'s Articles
[Chen Xiao-Hua]'s Articles
Baidu academic
Similar articles in Baidu academic
[Wu Di]'s Articles
[Yin Ying]'s Articles
[Chen Xiao-Hua]'s Articles
Bing Scholar
Similar articles in Bing Scholar
[Wu Di]'s Articles
[Yin Ying]'s Articles
[Chen Xiao-Hua]'s Articles
Terms of Use
No data!
Social Bookmark/Share
All comments (0)
No comment.
 

Items in the repository are protected by copyright, with all rights reserved, unless otherwise indicated.