PortScout: A Communication Flow-Based Approach to Detect Port Scanning Evasion Attacks
Muhammad Sangeen, Naveed Anwar Bhatti, Kashif Kifayat · 2025
Port scanning is a fundamental technique used by attackers to identify open ports, services, and vulnerabilities in target systems. Advanced evasion methods such as distributed scanning, slow scanning, and decoy scanning enable them to bypass traditional detection systems that are often resource-intensive and limited in scope. We introduce PortScout, a novel lightweight detection approach designed to identify port scanning evasion attacks efficiently. Unlike existing methods, PortScout leverages a unique flow aggregation and anomaly scoring mechanism that analyzes communication flows using only three key packet attributes: source IP, destination IP, and destination port. Despite the minimal data requirements, our method maintains high detection accuracy. Evaluated on real-time benign traffic and a diverse set of port scanning attacks, our approach achieves an average attack detection rate (AADR) of 89.5 % and a low false positive rate (AFPR) of 0.34 %. Additionally, it operates with low computational overhead, making it suitable for real-time deployment in high-speed networks. Compared to state-of-the-art methods, our solution offers a robust balance of efficiency and effectiveness, addressing the limitations of existing systems in detecting sophisticated port scanning evasion attacks.