DocumentCode :
1459938
Title :
A Network Activity Classification Schema and Its Application to Scan Detection
Author :
Treurniet, Joanne
Author_Institution :
Defence R&D Canada, Ottawa, ON, Canada
Volume :
19
Issue :
5
fYear :
2011
Firstpage :
1396
Lastpage :
1404
Abstract :
Internet traffic is neither well-behaved nor well-understood, which makes it difficult to detect malicious activities such as scanning. A large portion of scanning activity is of a slow scan type and is not currently detectable by security appliances. In this proof-of-concept study, a new scan detection technique is demonstrated that also improves our understanding of Internet traffic. Sessions are created using models of the behavior of packet-level data between host pairs, and activities are identified by grouping sessions based on patterns in the type of session, the IP addresses, and the ports. In a 24-h data set of nearly 10 million incoming sessions, a prodigious 78% were identified as scan probes. Of the scans, 80% were slower than basic detection methods can identify. To manage the large volume of scans, a prioritization method is introduced wherein scans are ranked based on whether a response was made and on the periodicity of the probes in the scan. The data is stored in an efficient manner, allowing activity information to be retained for very long periods of time. This technique provides insight into Internet traffic by classifying known activities, giving visibility to threats to the network through scan detection, while also extending awareness of the activities occurring on the network.
Keywords :
IP networks; Internet; security of data; telecommunication security; IP address; Internet traffic; activity information; malicious activity detection; network activity classification schema; packet-level data; periodicity; scan detection; scan probes; scanning activity; time 24 h; Backscatter; Computer crime; IP networks; Internet; Probes; Protocols; Sockets; Security and protection; system management; traffic analysis;
fLanguage :
English
Journal_Title :
Networking, IEEE/ACM Transactions on
Publisher :
ieee
ISSN :
1063-6692
Type :
jour
DOI :
10.1109/TNET.2011.2109009
Filename :
5720528
Link To Document :
بازگشت