Scan Surveillance in Internet Networks (Work in Progress)
Khadija Ramah Houerbi, K avSalamatian, Farouk Kamoun · 2009
In recent years, many measurement studies have shown the ubiquity of scanning activities in the Internet and the growing sophis- tication of probing techniques that became more stealthy by stretching slowly over time or using spoofed source IP addresses. Scans are mainly generated by attackers trying to map the configuration of a target net- work and by computer worms trying to spread over the Internet. Al- though, the problem of scan detection has been given a lot of attention by network security researchers, current state-of-the-art methods still suffer from high percentage of false alarms or low ratio of scan detection. In this paper, we propose to detect changes in scanning patterns, by monitor variation of the distribution of scan features in a space spanned by IP source address, IP destination address, source port number, and destination port number. This gives insight on characteristics of scan- ning activities and exposes the presence of emerging scanning attacks and worms. For that, we propose to use an information theoretic-based approach to detect changes in distributions.