Paper
9 August 2004 Detecting network portscans through anomoly detection
Hyukjoon Kim, Surrey Kim, Michael Alexander Kouritzin, Wei Sun
Author Affiliations +
Abstract
In this note, we consider the problem of detecting network portscans through the use of anomaly detection. First, we introduce some static tests for analyzing traffic rates. Then, we make use of two dynamic chi-square tests to detect anomalous packets. Further, we model network traffic as a marked point process and introduce a general portscan model. Simulation results for correct detects and false alarms are presented using this portscan model and the statistical tests.
© (2004) COPYRIGHT Society of Photo-Optical Instrumentation Engineers (SPIE). Downloading of the abstract is permitted for personal use only.
Hyukjoon Kim, Surrey Kim, Michael Alexander Kouritzin, and Wei Sun "Detecting network portscans through anomoly detection", Proc. SPIE 5429, Signal Processing, Sensor Fusion, and Target Recognition XIII, (9 August 2004); https://doi.org/10.1117/12.546127
Lens.org Logo
CITATIONS
Cited by 10 scholarly publications.
Advertisement
Advertisement
RIGHTS & PERMISSIONS
Get copyright permission  Get copyright permission on Copyright Marketplace
KEYWORDS
Computing systems

Performance modeling

Smoothing

Analytical research

Statistical analysis

Statistical modeling

Computer simulations

RELATED CONTENT


Back to Top