Stochastic analysis of horizontal IP scanning

Stochastic analysis of horizontal IP scanning
复制标题

水平IP扫描的随机分析

DOI:
10.1109/infcom.2012.6195589
复制
发表时间:
2012
期刊:
2012 Proceedings IEEE INFOCOM
影响因子:
--
通讯作者:
D. Loguinov
D. Loguinov
中科院分区:
--
文献类型:
--
作者:
Derek Leonard;Z. Yao;Xiaoming Wang;D. Loguinov

文献摘要

被引文献

相似文献

入侵检测系统(入侵检测系统)在防御病毒爆发、恶意利用操作系统漏洞和僵尸网络扩散方面变得无处不在。由于攻击者经常依赖主机扫描进行侦察,从而导致渗透,因此入侵检测系统的任务通常是检测和阻止扫描。然而,目前还不知道入侵检测系统检测到给定的互联网范围扫描模式的可能性有多大,以及是否存在足够快的扫描技术,可以在大规模情况下保持几乎不可检测的状态。为了解决这些问题,我们为流行的入侵检测工具(即Snort和Bro)的窗口过期规则提出了一个简单的分析模型,并利用Chen-Stein定理的一个变体来推导它们检测到一些常用扫描排列的概率。利用这一分析,我们还证明了隐身最优扫描模式的存在,检查了它们的性能,并将其与众所周知的技术进行了比较。
Intrusion Detection Systems (IDS) have become ubiquitous in the defense against virus outbreaks, malicious exploits of OS vulnerabilities, and botnet proliferation. As attackers frequently rely on host scanning for reconnaissance leading to penetration, IDS is often tasked with detecting scans and preventing them. However, it is currently unknown how likely an IDS is to detect a given Internet-wide scan pattern and whether there exist sufficiently fast scan techniques that can remain virtually undetectable at large-scale. To address these questions, we propose a simple analytical model for the window-expiration rules of popular IDS tools (i.e., Snort and Bro) and utilize a variation of the Chen-Stein theorem to derive the probability that they detect some of the commonly used scan permutations. Using this analysis, we also prove the existence of stealth-optimal scan patterns, examine their performance, and contrast it with that of well-known techniques.