A Bitmap-Based Algorithm for Detecting Stealthy Superpoints

Zhimin Li, Weijiang Liu, Zhiyang Li, Jingxia Sun · 2014

The host cardinality refers to the number of different peers that an Internet host communicates with. Stealthy superpoint is a host that its cardinality is between two thresholds during a measurement period. Detecting stealthy superpoints helps intrusion systems identify potential attackers. However, stealthy superpoints may perform scanning deliberately at a low rate, and they can easily evade the detection. The existing algorithm can not directly be used to detect them. This paper proposes an algorithm based on Bitmap which can detect stealthy superpoints. The algorithm includes online module and offline module. The online module consists of two submodules. One uses a bloom filter to filter the duplicate packets and store the source addresses. The other uses two-dimensional bit arrays to process packets. The offline estimates the cardinality. The theoretical analysis and experimental results show that our algorithm can precisely detect stealthy superpoints and estimate their cardinalities.

Read the paper · More papers on PaperTik