TY - JOUR
T1 - A behavior-based method for detecting distributed scan attacks in darknets
AU - Feng, Yaokai
AU - Hori, Yoshiaki
AU - Sakurai, Kouichi
AU - Takeuchi, Jun'ichi
PY - 2013
Y1 - 2013
N2 - The technologies used by attackers in the Internet environment are becoming more and more sophisticated. Of the many kinds of attacks, distributed scan attacks have become one of the most serious problems. In this study, we propose a novel method based on normal behavior modes of traffic to detect distributed scan attacks in darknet environments. In our proposed method, all the possible destination TCP and UDP ports are monitored, and when a port is attacked by a distributed scan, an alert is given. Moreover, the alert can have several levels reflecting the relative scale of the attack. To accelerate learning and updating the normal behavior modes and to realize rapid detection, an index is introduced, which is proved to be very efficient. The efficiency of our proposal is verified using real darknet traffic data. Although our proposal focuses on darknets, the idea can also be applied to ordinary networks.
AB - The technologies used by attackers in the Internet environment are becoming more and more sophisticated. Of the many kinds of attacks, distributed scan attacks have become one of the most serious problems. In this study, we propose a novel method based on normal behavior modes of traffic to detect distributed scan attacks in darknet environments. In our proposed method, all the possible destination TCP and UDP ports are monitored, and when a port is attacked by a distributed scan, an alert is given. Moreover, the alert can have several levels reflecting the relative scale of the attack. To accelerate learning and updating the normal behavior modes and to realize rapid detection, an index is introduced, which is proved to be very efficient. The efficiency of our proposal is verified using real darknet traffic data. Although our proposal focuses on darknets, the idea can also be applied to ordinary networks.
UR - http://www.scopus.com/inward/record.url?scp=84880150397&partnerID=8YFLogxK
UR - http://www.scopus.com/inward/citedby.url?scp=84880150397&partnerID=8YFLogxK
U2 - 10.2197/ipsjjip.21.527
DO - 10.2197/ipsjjip.21.527
M3 - Article
AN - SCOPUS:84880150397
SN - 0387-5806
VL - 21
SP - 527
EP - 538
JO - Journal of information processing
JF - Journal of information processing
IS - 3
ER -