Para acceder a los documentos con el texto completo, por favor, siga el siguiente enlace:

A practical approach to portscan detection in very high-speed links
Mikians, Jakub; Barlet Ros, Pere; Sanjuàs Cuxart, Josep; Solé Pareta, Josep
Universitat Politècnica de Catalunya. Departament d'Arquitectura de Computadors; Universitat Politècnica de Catalunya. CBA - Sistemes de Comunicacions de Banda Ampla
Port scans are continuously used by both worms and human attackers to probe for vulnerabilities in Internet facing systems. In this paper, we present a new method to efficiently detect TCP port scans in very high-speed links. The main idea behind our approach is to early discard those handshake packets that are not strictly needed to reliably detect port scans. We show that with just a couple of Bloom filters to track active servers and TCP handshakes we can easily discard about 85% of all handshake packets with negligible loss in accuracy. This significantly reduces both the memory requirements and CPU cost per packet. We evaluated our algorithm using packet traces and live traffic from 1 and 10 GigE academic networks. Our results show that our method requires less than 1 MB to accurately monitor a 10 Gb/s link, which perfectly fits in the cache memory of nowadays’ general-purpose processors.
Peer Reviewed
Àrees temàtiques de la UPC::Enginyeria electrònica i telecomunicacions::Telemàtica i xarxes d'ordinadors::Xarxes de banda ampla
Port scanner
Very high-speed links
TCP ports
Escàner de ports (Informàtica)
Attribution-NonCommercial-NoDerivs 3.0 Spain
Springer Verlag

Mostrar el registro completo del ítem

Documentos relacionados

Otros documentos del mismo autor/a

Sanjuàs Cuxart, Josep; Barlet Ros, Pere; Solé Pareta, Josep; Andriuzzi, Gabriella
Barlet Ros, Pere; Sanjuàs Cuxart, Josep; Solé Pareta, Josep; Gandía, Maria Isabel; Malagón, Chelo
Mikians, Jakub; Laoutaris, Nikolaos; Dhamdhere, Amogh; Barlet Ros, Pere
Sanjuàs Cuxart, Josep; Barlet Ros, Pere; Duffield, Nick; Kompella, Ramana
Sanjuàs Cuxart, Josep; Barlet Ros, Pere; Duffield, Nick; Kompella, Ramana