Title
Impact of Packet Sampling on Portscan Detection
Abstract
Packet sampling is commonly deployed in high-speed backbone routers to minimize resources used for network monitoring. It is known that packet sampling distorts traffic statistics and its impact has been extensively studied for traffic engineering metrics such as flow size and mean rate. However, it is unclear how packet sampling impacts anomaly detection, which has become increasingly critical to network providers. This paper is the first attempt to address this question by focusing on one common class of nonvolume-based anomalies, portscans, which are associated with worm/virus propagation. Existing portscan detection algorithms fall into two general approaches: target-specific and traffic profiling. We evaluated representative algorithms for each class, namely: 1) TRWSYN that performs stateful traffic analysis; 2) TAPS that tracks connection pattern of scanners; and 3) entropy-based traffic profiling. We applied these algorithms to detect portscans in both the original and sampled packet traces from a Tier-1 provider's backbone network. Our results demonstrate that sampling introduces fundamental bias that degrades the effectiveness of these detection algorithms and dramatically increases false positives. Through both experiments and analysis, we identify the traffic features critical for anomaly detection that are affected by sampling. Finally, using insight gained from this study, we show how portscan algorithms can be enhanced to be more robust to sampling
Year
DOI
Venue
2006
10.1109/JSAC.2006.884027
IEEE Journal on Selected Areas in Communications
Keywords
DocType
Volume
Sampling methods,Telecommunication traffic,Spine,Detection algorithms,Monitoring,Statistics,Performance evaluation,Pattern analysis,Performance analysis,Algorithm design and analysis
Journal
24
Issue
ISSN
Citations 
12
0733-8716
40
PageRank 
References 
Authors
2.26
17
5
Name
Order
Citations
PageRank
Jianning Mai134218.63
Ashwin Sridharan272455.79
Chen-Nee Chuah346933.71
Hui Zang4105277.25
Tao Ye51528.07