IP Technologies White Papers
Implementing Real Time Port Scan Detection for the IP Backbone
Overview Port scanning is prevalent in today's Internet and often has malicious intent. Although many algorithms have been proposed for different aspects of the scan detection problem, the paper has seen few system discussions in the literature. Furthermore, the few existing systems are designed for enterprise gateway level Intrusion Detection. Targeting the IP backbone, the paper puts all the pieces together in an implementation of an online port scan detecting and tracking system for high speed networks. The paper introduces the flexible architecture, discusses trade-offs and design choices. Specifically, it goes in depth to two design choices: the probabilistic counter selection and the buffer size tuning. The choice of a simple counter is validated through an empirical analysis of trace simulation.
| Publisher | Sprint | File Format | |
|---|---|---|---|
| Date Published | February 2007 | ||
| Format | White Papers | ||
| Topics | |||



