2009
DOI: 10.1007/978-3-642-01645-5_4
|View full text |Cite
|
Sign up to set email alerts
|

Portscan Detection with Sampled NetFlow

Abstract: Abstract. Sampling techniques are often used for traffic monitoring in high-speed links in order to avoid saturation of network resources. Although there is a wide existing research dealing with anomaly detection, few studies analyzed the impact of sampling on the performance of portscan detection algorithms. In this paper, we performed several experiments on two already existing portscan detection mechanisms to test whether they are robust enough to different sampling techniques. Unlike previous works, we fou… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
3
2

Citation Types

0
17
0

Year Published

2010
2010
2013
2013

Publication Types

Select...
4
3
1

Relationship

2
6

Authors

Journals

citations
Cited by 21 publications
(17 citation statements)
references
References 8 publications
0
17
0
Order By: Relevance
“…In the field of anomaly detection, several works have analyzed the impact of different sampling techniques on the performance of portscan detection [52][53][54]. They also conclude that packet sampling has an important impact on the detection accuracy, increasing both false negative and false positive ratios.…”
Section: Related Workmentioning
confidence: 99%
“…In the field of anomaly detection, several works have analyzed the impact of different sampling techniques on the performance of portscan detection [52][53][54]. They also conclude that packet sampling has an important impact on the detection accuracy, increasing both false negative and false positive ratios.…”
Section: Related Workmentioning
confidence: 99%
“…This paper uses a a compressed representation of Netflows similar to Aguri [10] for IP packets. There are other alternatives for a scalable storage and representation of flows data [4], [22], [23]. The authors of [22] introduce a column-oriented technique for storing data which provides a better scalability than common solutions relying on row-based techniques.…”
Section: Related Workmentioning
confidence: 99%
“…The authors of [22] introduce a column-oriented technique for storing data which provides a better scalability than common solutions relying on row-based techniques. Sampling [4], [23] can also highly reduce the volume of data, but setting a proper sampling rate is still a major issue.…”
Section: Related Workmentioning
confidence: 99%
“…RELATED WORK Few previous works have analyzed the impact of sampling on scan detection [8], [11], [10], [12]. In particular, the impact of Packet Sampling on TRW and TAPS was analyzed in [11].…”
Section: Introductionmentioning
confidence: 99%
“…This was a despairing result as routers only implement Packet Sampling. In [12] we presented a preliminary study of the performance of Packet Sampling using the same fraction of packets and showed that under some scenarios it could outperform Flow Sampling. Moreover, in [10], Androulidakis et al show that opportunistic flowbased techniques that target a certain part of the traffic can improve the performance of cyberattack detection algorithms under sampling w.r.t.…”
Section: Introductionmentioning
confidence: 99%