Scheduled System Maintenance:
Some services will be unavailable Sunday, March 29th through Monday, March 30th. We apologize for the inconvenience.
By Topic

A probabilistic approach to detecting network scans

Sign In

Cookies must be enabled to login.After enabling cookies , please use refresh or reload or ctrl+f5 on the browser for the login options.

The purchase and pricing options are temporarily unavailable. Please try again later.
2 Author(s)
Leckie, C. ; Dept. of Electr. & Electron. Eng., Melbourne Univ., Parkville, Vic., Australia ; Kotagiri, R.

This paper presents a probabilistic approach for detecting network scans in real-time. Unlike previous approaches, our model takes into consideration both the number of destinations or ports accessed by a source, as well as how unusual these accesses are. We demonstrate the effectiveness of our approach in terms of accuracy and throughput, based on an analysis of the unusual sources that were found in real-life packet trace files.

Published in:

Network Operations and Management Symposium, 2002. NOMS 2002. 2002 IEEE/IFIP

Date of Conference:

2002