an access-context based method to detect network scanning event in lan
文献类型:会议论文
作者 | Wu Di ; Yin Ying ; Chen Xiao-Hua ; Bu Ning |
出版日期 | 2009 |
会议名称 | International Conference on Machine Learning and Cybernetics |
会议日期 | JUL 12-15, |
会议地点 | Baoding, PEOPLES R CHINA |
关键词 | Network security network monitoring network scanning intrusion detection |
英文摘要 | Usually there are leading DNS resolution operations in normal network access scenarios and at the same time the relative connection success ratio is very high; but there is no leading DNS resolution operation in network scanning scenarios and the relative connection success ratio is very low. For convenience in this paper we named the network access connection attempt without leading DNS resolution operation as Suspicious Network Access (SNA). A network scanning detection approach is proposed in this paper by the analysis of SNAs response ratio and the randomness of their target IP addresses for each host in LAN. Since the proposed approach only takes the SNAs into account and the interference from normal network access can be decreased effectively, it can detect network scanning attacks with high accuracy and efficiency. The experiment results in simulation network scenario showed that the proposed approach support the detection of TCP-SYN and ICMP type network scanning attacks and also support the detection of stealth network scanning attacks as well. |
会议主办者 | Hebei Univ, IEEE Syst, Man & Cybernet Soc, Chongqing Univ, S China Univ Technol, Honk Kong Baptist Univ, Hebei Univ Sci & Technol |
会议录 | Proceedings of the 2009 International Conference on Machine Learning and Cybernetics
![]() |
会议录出版者 | PROCEEDINGS OF 2009 INTERNATIONAL CONFERENCE ON MACHINE LEARNING AND CYBERNETICS, VOLS 1-6 |
会议录出版地 | 345 E 47TH ST, NEW YORK, NY 10017 USA |
ISBN号 | 978-1-4244-4705-3 |
源URL | [http://124.16.136.157/handle/311060/8200] ![]() |
专题 | 软件研究所_信息安全国家重点实验室_会议论文 |
推荐引用方式 GB/T 7714 | Wu Di,Yin Ying,Chen Xiao-Hua,et al. an access-context based method to detect network scanning event in lan[C]. 见:International Conference on Machine Learning and Cybernetics. Baoding, PEOPLES R CHINA. JUL 12-15,. |
入库方式: OAI收割
来源:软件研究所
浏览0
下载0
收藏0
其他版本
除非特别说明,本系统中所有内容都受版权保护,并保留所有权利。