Title :
Scan detection under sampling: a new perspective
Author :
Paredes-Oliva, I. ; Barlet-Ros, Pere ; Sole-Pareta, Josep
Author_Institution :
Univ. Politec. de Catalunya BarcelonaTech, Barcelona, Spain
Abstract :
In tests using the same fraction of packets for comparison, packet sampling outperformed flow sampling for scan detection, while both selective sampling and a proposed extension that uses significantly less resources were superior to either of these techniques. The Web extra at http://youtu.be/Mgf8_a0fRs0 is a slide show that considers how in tests using the same fraction of packets for comparison, packet sampling outperformed flow sampling for scan detection, while both selective sampling and a proposed extension that uses significantly less resources were superior to either technique.
Keywords :
security of data; flow sampling; packet sampling; scan detection; selective sampling; Computer crime; Computer security; Detection algorithms; Memory management; Monitoring; Sampling methods; network security; scan detection; traffic sampling;