Back to Search
Start Over
Deep Mining Port Scans from Darknet
- Source :
- International Journal of Network Management, International Journal of Network Management, Wiley, 2019, Special Issue: Advanced Security Management, 29 (3), pp.e2065. ⟨10.1002/nem.2065⟩, International Journal of Network Management, 2019, Special Issue: Advanced Security Management, 29 (3), pp.e2065. ⟨10.1002/nem.2065⟩
- Publication Year :
- 2019
- Publisher :
- HAL CCSD, 2019.
-
Abstract
- International audience; TCP/UDP port scanning or sweeping is one of the most common technique used by attackers to discover accessible and potentially vulnerable hosts and applications. Although extracting and distinguishing different port scanning strategies is a challenging task, the identification of dependencies among probed ports is primordial for profiling attacker behaviors, with as a final goal to better mitigate them. In this paper, we propose an approach that allows to track port scanning behavior patterns among multiple probed ports and identify intrinsic properties of observed group of ports. Our method is fully automated based on graph modeling and data mining techniques including text mining. It provides to security analysts and operators relevant information about services that are jointly targeted by attackers. This is helpful to assess the strategy of the attacker, such that understanding the types of applications or environment she targets. We applied our method to data collected through a large Internet telescope (or Darknet).
- Subjects :
- Computer Networks and Communications
Computer science
graph theory
02 engineering and technology
computer.software_genre
[INFO.INFO-NI]Computer Science [cs]/Networking and Internet Architecture [cs.NI]
0202 electrical engineering, electronic engineering, information engineering
User Datagram Protocol
Profiling (information science)
Clustering coefficient
business.industry
Darknet
020206 networking & telecommunications
Graph theory
data mining
semantic port similarity
Port (computer networking)
Computer Science Applications
Deep mining
graph clustering
020201 artificial intelligence & image processing
The Internet
Data mining
port scanning
business
computer
darknet
Subjects
Details
- Language :
- English
- ISSN :
- 10557148 and 10991190
- Database :
- OpenAIRE
- Journal :
- International Journal of Network Management, International Journal of Network Management, Wiley, 2019, Special Issue: Advanced Security Management, 29 (3), pp.e2065. ⟨10.1002/nem.2065⟩, International Journal of Network Management, 2019, Special Issue: Advanced Security Management, 29 (3), pp.e2065. ⟨10.1002/nem.2065⟩
- Accession number :
- edsair.doi.dedup.....488acc768a0e4c91f5ea51cdfe0cf40c
- Full Text :
- https://doi.org/10.1002/nem.2065⟩