Knowledge Discovery of Port Scans from Darknet - Archive ouverte HAL Accéder directement au contenu
Communication Dans Un Congrès Année : 2017

Knowledge Discovery of Port Scans from Darknet

Sofiane Lagraa
  • Fonction : Auteur
  • PersonId : 770381
  • IdRef : 202656446

Résumé

Port scanning is widely used in Internet prior for attacks in order to identify accessible and potentially vulnerable hosts. In this work, we propose an approach that allows to discover port scanning behavior patterns and group properties of port scans. This approach is based on graph modelling and graph mining. It provides to security analysts relevant information of what services are jointly targeted, and the relationship of the scanned ports. This is helpful to assess the skills and strategy of the attacker. We applied our method to data collected from a large darknet data, i.e. a full /20 network where no machines or services are or have been hosted to study scanning activities.
Fichier principal
Vignette du fichier
annet.pdf (375.85 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)
Loading...

Dates et versions

hal-01636215 , version 1 (16-11-2017)

Identifiants

  • HAL Id : hal-01636215 , version 1

Citer

Sofiane Lagraa, Jerome Francois. Knowledge Discovery of Port Scans from Darknet. IFIP/IEEE Symposium on Integrated Network and Service Management (IM) - AnNet workshop, May 2017, Lisbonne, Portugal. ⟨hal-01636215⟩
186 Consultations
1674 Téléchargements

Partager

Gmail Facebook X LinkedIn More