A flow based slow and fast scan detection system

0Citations
Citations of this article
4Readers
Mendeley users who have this article in their library.
Get full text

Abstract

Attackers perform port scan to find reachability, liveness and services in a system or network. Current day scanning tools provide different scanning options and capable of evading various security tools like firewall, IDS and IPS. So in order to detect and prevent attacks in early stages, an accurate detection of scanning activity in real time is very much essential. In this paper we present a flow based protocol behavior analysis system to detect TCP based slow and fast scan. This system provides scalable, accurate and generic solution to TCP based scanning by means of automatic behavior analysis of the network traffic. Detection capability of proposed system is compared with SNORT and results proves the high detection rate of the system over SNORT. © 2010 Springer-Verlag Berlin Heidelberg.

Cite

CITATION STYLE

APA

Muraleedharan, N., & Parmar, A. (2010). A flow based slow and fast scan detection system. In Communications in Computer and Information Science (Vol. 89 CCIS, pp. 191–200). https://doi.org/10.1007/978-3-642-14478-3_20

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free