Scanner Detection Based on Connection Attempt Success Ratio with Guaranteed False Positive and False Negative Probabilities
نویسندگان
چکیده
Since the link rate is very high up to 40Gbps these days, scanning packets can spread very fast. At this high speed, only a small chance of missing on-going scanning activity can lead to catastrophic results. Thus, fast and accurate detection of scanners is a very important problem. High-speed packet processing usually requires high-speed memory, SRAM, and the size of SRAM is very limited compared with DRAM. We propose a connection attempt success ratio based scanning detection scheme which guarantees false positive and false negative probabilities under a memory-limited environment. Our scheme can also detect slow scanners with guaranteed performance. A sampling-based extended version can overcome the limitation of short-history-based scanning detection schemes and detects enhanced scanners with a list of pre-acquired IP addresses with guaranteed performance. The proposed scheme reduces the required memory size from O(N) to O(N), where N is the number of active hosts. We apply Bloom filter in order to further reduce the memory size. We evaluate the performance of the proposed scheme through simulation.
منابع مشابه
Retraining over the principles and mechanisms involved in the occurrence of false results from urine drug screening tests: Adulteration and strategies to defeat
Screening tests (UDSTs) for the diagnosis of psychoactive drugs can identify drug abuse, improve workplace safety, ensure community health, and play a critical role in therapeutic drug monitoring. Nonetheless, correct interpretation of the results of these tests requires a full awareness of the principles of testing methods, drug kinetics, and various leading causes of false results. Among the ...
متن کاملElectronic Money Laundering Detection in Transactions of Payment Service Providers
Under the coverage of legitimate commerce, criminals money-launder their illicit incomes through the payment gateways provided by Payment Service Providers (PSP). In order to do money-laundering forensics in transactions of PSP companies, a new method was proposed by Hojati et al which is done through detecting deviations from class behavior based on peer group analysis (PGA) method. Our experi...
متن کاملStatistical study of 45 false negative cases of Down syndrome in the first trimester screening protocol during 2015-2016 and introduction of a new criterion (Ratio> 3.0 of free BhCG MoM/PAPP-A MoM) to increase the efficacy of first trimester screenin
Introduction: Down syndrome screening has become an important part of antenatal care and is performed for pregnant women worldwide. In this study, 45 statistically accurate cases of false negatives in the first trimester screening tests have been examined statistically, so that by paying attention to some criteria, we can find out how many of these cases can be detected and how much each criter...
متن کاملA hybrid approach for database intrusion detection at transaction and inter-transaction levels
Nowadays, information plays an important role in organizations. Sensitive information is often stored in databases. Traditional mechanisms such as encryption, access control, and authentication cannot provide a high level of confidence. Therefore, the existence of Intrusion Detection Systems in databases is necessary. In this paper, we propose an intrusion detection system for detecting attacks...
متن کاملFalse Negative Fecal Occult Blood Test: Prozone Effect
Dear editor, the fecal occult blood test is the presently widely used screening laboratory test for colorectal cancer. At present, the test is usually based on an immunological diagnostic principle (1, 2). A false positive fecal occult blood is common and widely mentioned in literature. Nevertheless, the false negative is little mentioned in the paper. Here, the authors discuss the issue of the...
متن کامل