【24h】

Portscan Detection with Sampled NetFlow

机译:PortScan检测使用采样NetFlow

获取原文

摘要

Sampling techniques are often used for traffic monitoring in high-speed links in order to avoid saturation of network resources. Although there is a wide existing research dealing with anomaly detection, few studies analyzed the impact of sampling on the performance of portscan detection algorithms. In this paper, we performed several experiments on two already existing portscan detection mechanisms to test whether they are robust enough to different sampling techniques. Unlike previous works, we found that flow sampling is not always better than packet sampling to continue detecting portscans reliably.
机译:采样技术通常用于高速链路中的流量监控,以避免网络资源的饱和度。虽然有一项涉及异常检测的研究,但很少有研究分析了采样对PortScan检测算法性能的影响。在本文中,我们对两个已经存在的PortScan检测机制进行了几个实验,以测试它们是否足够强大,以便对不同的采样技术进行足够强大。与以前的作品不同,我们发现流采样并不总是比数据包采样更好,以便可靠地继续检测PORSCAN。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号