Title
A practical approach to portscan detection in very high-speed links
Abstract
Port scans are continuously used by both worms and human attackers to probe for vulnerabilities in Internet facing systems. In this paper, we present a new method to efficiently detect TCP port scans in very high-speed links. The main idea behind our approach is to early discard those handshake packets that are not strictly needed to reliably detect port scans. We show that with just a couple of Bloom filters to track active servers and TCP handshakes we can easily discard about 85% of all handshake packets with negligible loss in accuracy. This significantly reduces both the memory requirements and CPU cost per packet. We evaluated our algorithm using packet traces and live traffic from 1 and 10 GigE academic networks. Our results show that our method requires less than 1 MB to accurately monitor a 10 Gb/s link, which perfectly fits in the cache memory of nowadays' general-purpose processors.
Year
DOI
Venue
2011
10.1007/978-3-642-19260-9_12
PAM
Keywords
Field
DocType
bloom filter,practical approach,port scan,cache memory,handshake packet,tcp port,high-speed link,memory requirement,gige academic network,cpu cost,packet trace,new method
Bloom filter,Handshake,Computer science,CPU cache,Server,Network packet,Computer network,Real-time computing,S-LINK,Hash table,The Internet
Conference
Volume
ISSN
Citations 
6579
0302-9743
2
PageRank 
References 
Authors
0.38
9
4
Name
Order
Citations
PageRank
Jakub Mikians1906.79
Pere Barlet-ros226927.74
Josep Sanjuàs-Cuxart3465.14
Josep Solé-pareta443658.67