• DocumentCode
    84500
  • Title

    Cyber Scanning: A Comprehensive Survey

  • Author

    Bou-Harb, Elias ; Debbabi, Mourad ; Assi, Chadi

  • Author_Institution
    Concordia Inst. for Inf. Syst. Eng., Canada
  • Volume
    16
  • Issue
    3
  • fYear
    2014
  • fDate
    Third Quarter 2014
  • Firstpage
    1496
  • Lastpage
    1519
  • Abstract
    Cyber scanning refers to the task of probing enterprise networks or Internet wide services, searching for vulnerabilities or ways to infiltrate IT assets. This misdemeanor is often the primarily methodology that is adopted by attackers prior to launching a targeted cyber attack. Hence, it is of paramount importance to research and adopt methods for the detection and attribution of cyber scanning. Nevertheless, with the surge of complex offered services from one side and the proliferation of hackers´ refined, advanced, and sophisticated techniques from the other side, the task of containing cyber scanning poses serious issues and challenges. Furthermore recently, there has been a flourishing of a cyber phenomenon dubbed as cyber scanning campaigns - scanning techniques that are highly distributed, possess composite stealth capabilities and high coordination - rendering almost all current detection techniques unfeasible. This paper presents a comprehensive survey of the entire cyber scanning topic. It categorizes cyber scanning by elaborating on its nature, strategies and approaches. It also provides the reader with a classification and an exhaustive review of its techniques. Moreover, it offers a taxonomy of the current literature by focusing on distributed cyber scanning detection methods. To tackle cyber scanning campaigns, this paper uniquely reports on the analysis of two recent cyber scanning incidents. Finally, several concluding remarks are discussed.
  • Keywords
    Internet; security of data; Internet wide services; cyber scanning technique; distributed cyber scanning detection method; enterprise networks; targeted cyber attack; Cyberspace; Internet; Monitoring; Ports (Computers); Probes; Protocols; Servers; Cyber scanning; Network reconnaissance; Probing; Probing campaigns; Scanning events;
  • fLanguage
    English
  • Journal_Title
    Communications Surveys & Tutorials, IEEE
  • Publisher
    ieee
  • ISSN
    1553-877X
  • Type

    jour

  • DOI
    10.1109/SURV.2013.102913.00020
  • Filename
    6657498