Automated Detection of Malicious Reconnaissance to Enhance Network Security

William Hand Allen, Gerald A. Marin, Louis Rivera · 2005

Anomaly detection tools currently react to directed attacks during or shortly after they have occurred. Unfortunately, an attack that is detected after it has occurred is, in essence, a successful one. Advance warning of potential attacks could aid in their detection. Before an attack is launched the attacker often performs reconnaissance on the target host or network to learn its vulnerabilities. If malicious network reconnaissance can be detected and identified, it can serve as a warning of future attacks and may provide clues as to the identity of the attacker. This paper presents a novel technique for the automated detection of malicious network reconnaissance in a live network.

Read the paper · More papers on PaperTik