DynamicWEB: A Method for Reconnaissance Activity Profiling | IEEE Conference Publication | IEEE Xplore

DynamicWEB: A Method for Reconnaissance Activity Profiling


Abstract:

Port scan correlation aims to differentiate between benign and malicious scans. In this paper we will examine a new method of profiling port scan activity in an attempt t...Show More

Abstract:

Port scan correlation aims to differentiate between benign and malicious scans. In this paper we will examine a new method of profiling port scan activity in an attempt to link different source IP addresses to being the same end user. A data mining approach DynamicWEB based upon the COBWEB conceptual clustering algorithm is shown along with some preliminary results of it functioning within the context of scan correlation.
Date of Conference: 10-12 December 2008
Date Added to IEEE Xplore: 22 December 2008
Print ISBN:978-0-7695-3471-8

ISSN Information:

Conference Location: Sydney, NSW, Australia

Contact IEEE to Subscribe

References

References is not available for this document.