...
首页> 外文期刊>EURASIP journal on information security >How can sliding HyperLogLog and EWMA detect port scan attacks in IP traffic?
【24h】

How can sliding HyperLogLog and EWMA detect port scan attacks in IP traffic?

机译:如何滑动超级历高和EWMA检测IP流量的端口扫描攻击?

获取原文
   

获取外文期刊封面封底 >>

       

摘要

IP networks are constantly targeted by new techniques of denial of service attacks (SYN flooding, port scan, UDP flooding, etc), causing service disruption and considerable financial damage. The on-line detection of DoS attacks in the current high-bit rate IP traffic is a big challenge. We propose in this paper an on-line algorithm for port scan detection. It is composed of two complementary parts: First, a probabilistic counting part, where the number of distinct destination ports is estimated by adapting a method called ‘sliding HyperLogLog’ to the context of port scan in IP traffic. Second, a decisional mechanism is performed on the estimated number of destination ports in order to detect in real time any behavior that could be related to a malicious traffic. This latter part is mainly based on the exponentially weighted moving average algorithm (EWMA) that we adapted to the context of on-line analysis by adding a learning step (supposed without attacks) and improving its update mechanism. The obtained port scan detecting method is tested against real IP traffic containing some attacks. It detects all the port scan attacks within a very short time response (of about 30 s) and without any false positive. The algorithm uses a very small total memory of less than 22 kb and has a very good accuracy on the estimation of the number of destination ports (a relative error of about 3.25 % ), which is in agreement with the theoretical bounds provided by the sliding HyperLogLog algorithm.
机译:IP网络不断通过拒绝服务攻击的新技术(SYN洪水,端口扫描,UDP洪水等),造成服务中断和相当大的经济损失。目前高比特率IP流量的DOS攻击的在线检测是一个很大的挑战。我们提出了一种用于端口扫描检测的在线算法。它由两个补充部分组成:首先,概率计数部分,其中通过将名为“滑动超字幕”的方法调整到IP流量中的端口扫描的上下文来估计不同的目的地端口的数量。其次,在估计的目标端口数量上执行致命机制,以便实时检测任何可能与恶意流量有关的行为。后一部分主要基于指数加权移动平均算法(EWMA),我们通过添加学习步骤(假设没有攻击)并改善其更新机制来适应在线分析的上下文。获得的端口扫描检测方法是针对包含某些攻击的真实IP流量进行测试。它检测到在非常短的时间响应(约30秒)内的所有端口扫描攻击,并且没有任何误报。该算法使用小于22 kB的非常小的总存储器,并且在目的地端口数(约3.25%的相对误差)的估计上具有非常好的准确性,这与滑动提供的理论界限一致HyperLoglog算法。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号