Coordinated Scan Detection Based on Similarities of Scan Behaviors ?
نویسندگان
چکیده
Coordinated scan can gather host information for further attack more efficiently and stealthily than single-source port scans by distributing tasks amongst multiple sources. The existing coordinated scan detection methods are mostly based on scan behavior characteristics in temporal or spatial correlation. However, these detection methods can be easily evaded with the increasingly sophisticated coordinated scan methods. In this paper, we propose an approach to detecting coordinated scans based on the similarities between the scan behavior sequences launched by the scanners. Based on the assumption that the scanners controlled by an attacker are similar in the scan behaviors, the coordinated scan detection problem can be reduced to that of recognizing the similar scan sequences. We first present a description model of coordinated scan. Then a detection algorithm is developed based on the Dynamic Time Warping (DTW) distances between the sequences and a hierarchical clustering method was used to recognize coordinated scanners. The experimental results suggest that the proposed method has an acceptable detection rate for horizontal scans, vertical scans and hybrid scans.
منابع مشابه
Diagnostic Accuracy of CT Scan for Detection of Cervical Lymph Node Metastasis in Oral Squamous Cell Carcinoma in Comparison with Histopathological Analysis After Neck Dissection
Objectives: Presence/absence of cervical lymph node metastasis plays a critical role in prognosis and survival of patients with oral squamous cell carcinoma (SCC). This study was designed to assess the diagnostic accuracy of computed tomography (CT) scan for detection of cervical lymph node metastasis in oral SCC in comparison with histopathological analysis after neck dissection Methods: In...
متن کاملAOCD: An Adaptive Outlier Based Coordinated Scan Detection Approach
Coordinated attacks are distributed in nature because they attempt to compromise a target machine from multiple sources. It is important for network defenders and administrators to detect these scans as possible preliminaries to more serious attacks. However, it is very difficult to detect malicious scans based on port specific behavior alone. In this paper, we present an Adaptive Outlier based...
متن کاملMyocardial perfusion scan accuracy in detection of coronary artery disease - Comparison with exercise stress test [Persian]
Introduction: In patients with coronary artery disease (CAD) noninvasive evaluation for detection of ischemia is important to avoid invasive interventions like angiography. Exercise stress test is conventionally the first study used in evaluation of CAD. Considering the noninvasive nature of the myocardial perfusion scan, we decided to compare its accuracy with stress test. Methods: Patie...
متن کاملDiagnosis of thromboembolic disease: Combined ventilation perfusion lung scan and compression ultrasonography
The clinical management of pulmonary embolism and deep venous thrombosis of the legs are similar and requires prolonged anticoagulation therapy. The standard diagnostic approach in patients suspected of pulmonary embolism is ventilation-perfusion (V/Q) lung scan and compression ultrasonography to detect deep venous thrombosis. This retrospective study analyzed the role of V/Q lung scan an...
متن کاملAccuracy Assessment of Ultrasonic C-scan and X-ray Radiography Methods for Impact Damage Detection in Glass Fiber Reinforced Polyester Composites
The present study introduces two quantitative parameters to compare the accuracy of ultrasonic C-scan testing and X-ray radiography methods in the damaged area detection under low-velocity impact in polymer-based composites. For this purpose, the hand lay-up technique of composite processing was employed to prepare the composite specimen. A composite specimen consisting of the glass fiber reinf...
متن کامل