IP Technologies White Papers

Implementing Real Time Port Scan Detection for the IP Backbone

Overview Port scanning is prevalent in today's Internet and often has malicious intent. Although many algorithms have been proposed for different aspects of the scan detection problem, the paper has seen few system discussions in the literature. Furthermore, the few existing systems are designed for enterprise gateway level Intrusion Detection. Targeting the IP backbone, the paper puts all the pieces together in an implementation of an online port scan detecting and tracking system for high speed networks. The paper introduces the flexible architecture, discusses trade-offs and design choices. Specifically, it goes in depth to two design choices: the probabilistic counter selection and the buffer size tuning. The choice of a simple counter is validated through an empirical analysis of trace simulation.

Further White Paper Details
PublisherSprint File FormatPDF
Date PublishedFebruary 2007
FormatWhite Papers   
Topics
  • Featured White Papers
Thin clients switch on digitally excluded

Thin clients switch on digitally excluded

Case study: Digital inclusion project tackles social exclusion in Liverpool more

Renault goes multilingual

Renault goes multilingual

Case study: Translation tech turns docs into 23 languages… more


Quick Sitemap Links: