A Bitmap-Based Algorithm for Detecting Stealthy Superpoints
Zhimin Li, Weijiang Liu, Zhiyang Li, Jingxia Sun · 2014
The host cardinality refers to the number of different peers that an Internet host communicates with. Stealthy superpoint is a host that its cardinality is between two thresholds during a measurement period. Detecting stealthy superpoints helps intrusion systems identify potential attackers. However, stealthy superpoints may perform scanning deliberately at a low rate, and they can easily evade the detection. The existing algorithm can not directly be used to detect them. This paper proposes an algorithm based on Bitmap which can detect stealthy superpoints. The algorithm includes online module and offline module. The online module consists of two submodules. One uses a bloom filter to filter the duplicate packets and store the source addresses. The other uses two-dimensional bit arrays to process packets. The offline estimates the cardinality. The theoretical analysis and experimental results show that our algorithm can precisely detect stealthy superpoints and estimate their cardinalities.