基于Internet协议识别码的理想隐身端口扫描检测

S. Patel, Abhilash Sonker
{"title":"基于Internet协议识别码的理想隐身端口扫描检测","authors":"S. Patel, Abhilash Sonker","doi":"10.1109/CICN.2016.89","DOIUrl":null,"url":null,"abstract":"Port scanning is a reconnaissance phase of networking and many researchers have implemented different techniques to secure the network from port scan attacks. Intrusion Detection System (IDS) is also one of them and SNORT is an open source tool for Intrusion Detection and Prevention System. Today port scanning is a growing technology in network security to perform penetration testing and hacking and mostly researchers have focused in this field to detect stealth port scan attacks named as FIN scan, XMUS and NULL scan. To detect these attacks some of them used signature or rule-based technique and some are anomaly based techniques to improve security of network. In above techniques rules used FIN, PSH, and URG flag to detect attack but in case of idle port scan attack rules used FIN and RST flags which is also part of TCP connect() method so using this flag directly will generate the false alarm. In this paper we propose an IP identification number based detection plug-in to detect idle port scan attack. In this proposed techniques we will able to detect the idle port scan attack using FIN and RST flag with IP ID number of packet.","PeriodicalId":189849,"journal":{"name":"2016 8th International Conference on Computational Intelligence and Communication Networks (CICN)","volume":"9 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2016-12-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"13","resultStr":"{\"title\":\"Internet Protocol Identification Number Based Ideal Stealth Port Scan Detection Using Snort\",\"authors\":\"S. Patel, Abhilash Sonker\",\"doi\":\"10.1109/CICN.2016.89\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Port scanning is a reconnaissance phase of networking and many researchers have implemented different techniques to secure the network from port scan attacks. Intrusion Detection System (IDS) is also one of them and SNORT is an open source tool for Intrusion Detection and Prevention System. Today port scanning is a growing technology in network security to perform penetration testing and hacking and mostly researchers have focused in this field to detect stealth port scan attacks named as FIN scan, XMUS and NULL scan. To detect these attacks some of them used signature or rule-based technique and some are anomaly based techniques to improve security of network. In above techniques rules used FIN, PSH, and URG flag to detect attack but in case of idle port scan attack rules used FIN and RST flags which is also part of TCP connect() method so using this flag directly will generate the false alarm. In this paper we propose an IP identification number based detection plug-in to detect idle port scan attack. In this proposed techniques we will able to detect the idle port scan attack using FIN and RST flag with IP ID number of packet.\",\"PeriodicalId\":189849,\"journal\":{\"name\":\"2016 8th International Conference on Computational Intelligence and Communication Networks (CICN)\",\"volume\":\"9 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2016-12-01\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"13\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2016 8th International Conference on Computational Intelligence and Communication Networks (CICN)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/CICN.2016.89\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2016 8th International Conference on Computational Intelligence and Communication Networks (CICN)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/CICN.2016.89","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 13

摘要

端口扫描是网络的一个侦察阶段,许多研究人员已经实现了不同的技术来保护网络免受端口扫描攻击。入侵检测系统(IDS)也是其中之一,而SNORT是用于入侵检测和防御系统的开源工具。如今,端口扫描在网络安全中是一种不断发展的技术,用于执行渗透测试和黑客攻击,大多数研究人员都集中在该领域检测隐形端口扫描攻击,称为FIN扫描,XMUS和NULL扫描。为了检测这些攻击,有的采用了基于签名或规则的技术,有的采用了基于异常的技术,以提高网络的安全性。在上述技术中,规则使用FIN, PSH和URG标志来检测攻击,但在空闲端口扫描的情况下,攻击规则使用FIN和RST标志,这也是TCP connect()方法的一部分,因此直接使用该标志将产生假警报。本文提出了一种基于IP识别码的检测插件来检测空闲端口扫描攻击。在这个提议的技术中,我们将能够检测空闲端口扫描攻击,使用FIN和RST标志与数据包的IP ID号。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
Internet Protocol Identification Number Based Ideal Stealth Port Scan Detection Using Snort
Port scanning is a reconnaissance phase of networking and many researchers have implemented different techniques to secure the network from port scan attacks. Intrusion Detection System (IDS) is also one of them and SNORT is an open source tool for Intrusion Detection and Prevention System. Today port scanning is a growing technology in network security to perform penetration testing and hacking and mostly researchers have focused in this field to detect stealth port scan attacks named as FIN scan, XMUS and NULL scan. To detect these attacks some of them used signature or rule-based technique and some are anomaly based techniques to improve security of network. In above techniques rules used FIN, PSH, and URG flag to detect attack but in case of idle port scan attack rules used FIN and RST flags which is also part of TCP connect() method so using this flag directly will generate the false alarm. In this paper we propose an IP identification number based detection plug-in to detect idle port scan attack. In this proposed techniques we will able to detect the idle port scan attack using FIN and RST flag with IP ID number of packet.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信