首页> 外文会议>IEEE International Conference on Signal Image Technology and Internet Based Systems >Detection of TCP SYN Scanning Using Packet Counts and Neural Network
【24h】

Detection of TCP SYN Scanning Using Packet Counts and Neural Network

机译:用分组计数和神经网络检测TCP SYN扫描

获取原文

摘要

Port Scanning is used by malicious users to mapthe characteristics of a network to launch furtherattacks. Hence, detection of port scanning assumesparamount importance. This paper investigates theeffectiveness of using counts of various TCP controlpackets in detecting TCP SYN scanning on a singlemachine. The behavioural characteristics of TCPcontrol packets are aggregated. A Neural Network istrained to capture this behaviour for normal as wellas port scan data. It is seen from the investigationthat the counts of TCP SYN, SYN-ACK and FINpackets show definite patterns in their behaviour forlegitimate connections. A deviation from thisbehaviour is used to effectively detect TCP SYNscanning without maintaining state information.
机译:恶意用户使用PORT扫描来映射网络的特性以启动overstAtcls。因此,检测端口扫描假设的重要性。本文研究了使用各种TCP ControlPackets在单次机器上检测TCP SYN扫描中的各种TCP ControlPackets的效力。聚合TCPControl数据包的行为特征。训练神经网络以捕获正常作为云端口扫描数据的这种行为。从调查中可以看出,TCP SYN,SYN-ACK和FINPackets的计数显示了他们的行为全面连接的明确模式。从此偏差用于有效地检测TCP SynScanning而不保持状态信息。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号