Port scanning detection based on anomalies
Евгений Викторович Ананьин, Никишова Арина Валерьевна, Irina S. Kozhevnikova · 2017
Modern companies can't operate and conduct business without using a developed and stable functioning information system, which includes a network. To monitor network performance characteristics of network traffic are often defined, the values of them determine the performance of the network. Mostly these characteristics values vary slightly within predetermined time intervals. A significant change in their values indicates a violation of network performance or the presence of anomalies. This article reviews the type of network anomalies, which is made by port scan. The article describes main types of port scans, and the peculiarities of the implementation of various types of scans. This data was used to construct a mathematical model for detecting anomalies caused by a port scan. An algorithm that implements the proposed mathematical model for detecting port scanning has been made. Software implementation of the algorithm makes it possible not only to determine the fact of the port scanning, but also to identify the source - IP-address of the attacker performing a scan.