Characteristics of Port Scan Traffic: A Case Study Using Nmap

4Citations
Citations of this article
49Readers
Mendeley users who have this article in their library.

Abstract

Network ports, essential for communication, become susceptible to port scanning techniques employed by cybersecurity professionals, network administrators, and malicious hackers. The study digs into the specific characteristics of Nmap-generated port scan traffic, examining patterns, behaviors, and data relations throughout the packets. Also, researchers investigate the relationships between various port scan features and approaches to provide insightful information for developing more effective intrusion detection systems. The tool Nmap, which is widely employed for reconnaissance attacks in current network security, is the subject of this paper, and the Metasploit tool is also used to illustrate specific behavior and how it differs from the Nmap tool. The paper's contribution is summarized by introducing features like source ports, destination port distribution, statistics, and time-related attributes, which can be used as distinguishable features to detect the scan traffic. The term "Indicator of Scan" (IoS), as used by the authors, refers to a broad category that includes any useful indicators for scan detection. IoS can also be useful in determining which specific scanning tool is utilized in addition to scan detection.

Cite

CITATION STYLE

APA

Al-Khazaali, Z., Al-Ghabban, A., Al-Musawi, H., Sabah, A., & Al Mahdi, N. (2025). Characteristics of Port Scan Traffic: A Case Study Using Nmap. Journal of Engineering and Sustainable Development, 29(1), 26–35. https://doi.org/10.31272/jeasd.2638

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free