首页> 外文会议>IFIP International Conference on New Technologies, Mobility and Security >Internet-Wide Scanners Classification using Gaussian Mixture and Hidden Markov Models
【24h】

Internet-Wide Scanners Classification using Gaussian Mixture and Hidden Markov Models

机译:使用高斯混合和隐马尔可夫模型的全互联网扫描仪分类

获取原文

摘要

Internet-wide scanners are heavily used for malicious activities. This work models, from the scanned system point of view, spatial and temporal movements of Network Scanning Activities (NSAs), related to the difference of successive scanned IP addresses and timestamps, respectively. Based on real logs of incoming IP packets collected from a darknet, Hidden Markov Models (HMMs) are used to assess what scanning tool is operating. The proposed methodology, using only one of the aforementioned features of the scanning tool, is able to fingerprint what network scanner originated the perceived darknet traffic.
机译:整个Internet的扫描仪都大量用于恶意活动。从被扫描的系统角度来看,该工作可以对网络扫描活动(NSA)的时空移动进行建模,分别与连续扫描的IP地址和时间戳的差异有关。根据从暗网收集的传入IP数据包的真实日志,使用隐马尔可夫模型(HMM)来评估正在运行的扫描工具。所提出的方法仅使用扫描工具的上述特征之一,就能够识别出哪些网络扫描仪源自感知到的暗网流量。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号