Interdisciplinary Research Theory and Technology 2013
DOI: 10.14257/astl.2013.29.01
|View full text |Cite
|
Sign up to set email alerts
|

Design of a Portscan Detection Scheme with Random Packet Sampling

Abstract: Abstract. We consider the parameter design of a TCP portscan detection scheme with packet sampling. We assume that anomalous hosts infected by worms or bots perform portscan and generate a large number of scanning TCP flows as well as its usual traffic. We regard a flow consisting of SYN packets only (SYN-only flow) as a portscan flow and attempt to detect hosts who generate θ SYN-only flows or more, where θ denotes the threshold. In this framework, we present a method for determining the threshold of sampled … Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...

Citation Types

0
0
0

Publication Types

Select...

Relationship

0
0

Authors

Journals

citations
Cited by 0 publications
references
References 9 publications
0
0
0
Order By: Relevance

No citations

Set email alert for when this publication receives citations?