【24h】

Detection of TCP SYN Scanning Using Packet Counts and Neural Network

机译:使用数据包计数和神经网络检测TCP SYN扫描

获取原文

摘要

Port Scanning is used by malicious users to mapthe characteristics of a network to launch furtherattacks. Hence, detection of port scanning assumesparamount importance. This paper investigates theeffectiveness of using counts of various TCP controlpackets in detecting TCP SYN scanning on a singlemachine. The behavioural characteristics of TCPcontrol packets are aggregated. A Neural Network istrained to capture this behaviour for normal as wellas port scan data. It is seen from the investigationthat the counts of TCP SYN, SYN-ACK and FINpackets show definite patterns in their behaviour forlegitimate connections. A deviation from thisbehaviour is used to effectively detect TCP SYNscanning without maintaining state information.
机译:恶意用户使用端口扫描来映射网络的特征,以发起进一步的攻击。因此,端口扫描的检测极为重要。本文研究了使用各种TCP控制包计数来检测单台机器上的TCP SYN扫描的有效性。 TCPcontrol数据包的行为特征被汇总。训练了一个神经网络以捕获正常以及端口扫描数据的此行为。从调查中可以看出,TCP SYN,SYN-ACK和FINpackets的数量在其合法连接行为中显示了确定的模式。与此行为的偏差用于有效地检测TCP SYN扫描,而无需维护状态信息。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号