Scan Detection on Very Large Networks Using Logistic Regression Modeling

Scan Detection on Very Large Networks Using Logistic Regression Modeling
复制标题

使用逻辑回归模型扫描超大型网络上的检测

DOI:
10.1109/iscc.2006.142
复制
发表时间:
2006
期刊:
11th IEEE Symposium on Computers and Communications (ISCC'06)
影响因子:
--
通讯作者:
M. Kellner
M. Kellner
中科院分区:
--
文献类型:
--
作者:
C. Gates;Josh McNutt;J. Kadane;M. Kellner

文献摘要

被引文献

相似文献

扫描活动是当今互联网上的常见活动,代表恶意活动,例如有动机的对手收集信息或搜索易受攻击主机的自动化工具(例如,蠕虫)。已经开发了许多扫描检测技术;然而,它们的重点一直放在较小的网络上,其中数据包级别的信息可用,或者网络的内部特性是已知的。对于大型网络,例如ISP、大型公司或政府组织的网络,可能无法获得此信息。本文提出了一种模型的扫描,可以使用只单向流数据。该模型使用贝叶斯逻辑回归,该回归是使用专家意见和手动分类的训练数据相结合开发的。当对一组300个TCP事件进行测试时,它的检测率为95.5%,假阳性率为0.4%。
Scanning activity is a common activity on the Internet today, representing malicious activity such as information gathering by a motivated adversary or automated tools searching for vulnerable hosts (e.g., worms). Many scan detection techniques have been developed; however, their focus has been on smaller networks where packet-level information is available, or where internal characteristics of the network are known. For large networks, such as those of ISPs, large corporations or government organizations, this information might not be available. This paper presents a model of scans that can be used given only unidirectional flow data. The model uses a Bayesian logistic regression, which was developed using a combination of expert opinion and manually-classified training data. It is shown to have a detection rate of 95.5% with a false positive rate of 0.4% overall when tested against a set of 300 TCP events.