Abstract
Attackers perform port scan to find reachability, liveness and services in a system or network. Current day scanning tools provide different scanning options and capable of evading various security tools like firewall, IDS and IPS. So in order to detect and prevent attacks in early stages, an accurate detection of scanning activity in real time is very much essential. In this paper we present a flow based protocol behavior analysis system to detect TCP based slow and fast scan. This system provides scalable, accurate and generic solution to TCP based scanning by means of automatic behavior analysis of the network traffic. Detection capability of proposed system is compared with SNORT and results proves the high detection rate of the system over SNORT. © 2010 Springer-Verlag Berlin Heidelberg.
Author supplied keywords
Cite
CITATION STYLE
Muraleedharan, N., & Parmar, A. (2010). A flow based slow and fast scan detection system. In Communications in Computer and Information Science (Vol. 89 CCIS, pp. 191–200). https://doi.org/10.1007/978-3-642-14478-3_20
Register to see more suggestions
Mendeley helps you to discover research relevant for your work.