
doi: 10.1109/itng.2009.16
Scanning activities are usually conducted by infected hosts to discover other vulnerable hosts or by a motivated adversary to gather information, and are typically precursor to most of the cyber attacks. There are many scan detection approaches at present; however, most of them focus on enterprise-level network where the traffic volume is low, bi-directional and packet-level information are available. This paper proposes a new port scan detection approach -- time based flow size distribution sequential hypothesis testing or TFDS briefly, for high-speed transit network where only unidirectional flow information is available. TFDS uses the main idea of sequential hypothesis testing to detect scanners that exhibit abnormal access patterns in terms of flow size distribution (FSD) entropy. We make a comparison with the state-of-the-art backbone port scan detection method TAPS [5] in terms of efficiency and effectiveness using real backbone packet trace, and find that TFDS performs much better than TAPS.
| selected citations These citations are derived from selected sources. This is an alternative to the "Influence" indicator, which also reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically). | 6 | |
| popularity This indicator reflects the "current" impact/attention (the "hype") of an article in the research community at large, based on the underlying citation network. | Average | |
| influence This indicator reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically). | Average | |
| impulse This indicator reflects the initial momentum of an article directly after its publication, based on the underlying citation network. | Average |
