Abstract:
Port scan correlation aims to differentiate between benign and malicious scans. In this paper we will examine a new method of profiling port scan activity in an attempt t...Show MoreMetadata
Abstract:
Port scan correlation aims to differentiate between benign and malicious scans. In this paper we will examine a new method of profiling port scan activity in an attempt to link different source IP addresses to being the same end user. A data mining approach DynamicWEB based upon the COBWEB conceptual clustering algorithm is shown along with some preliminary results of it functioning within the context of scan correlation.
Published in: 2008 IEEE International Symposium on Parallel and Distributed Processing with Applications
Date of Conference: 10-12 December 2008
Date Added to IEEE Xplore: 22 December 2008
Print ISBN:978-0-7695-3471-8