Title
Knowledge discovery of port scans from darknet.
Abstract
Port scanning is widely used in Internet prior for attacks in order to identify accessible and potentially vulnerable hosts. In this work, we propose an approach that allows to discover port scanning behavior patterns and group properties of port scans. This approach is based on graph modelling and graph mining. It provides to security analysts relevant information of what services are jointly targeted, and the relationship of the scanned ports. This is helpful to assess the skills and strategy of the attacker. We applied our method to data collected from a large darknet data, i.e. a full /20 network where no machines or services are or have been hosted to study scanning activities.
Year
Venue
Field
2017
IM
Graph,Port (computer networking),World Wide Web,Computer science,Darknet,Computer network,Knowledge extraction,The Internet
DocType
Citations 
PageRank 
Conference
3
0.44
References 
Authors
7
2
Name
Order
Citations
PageRank
Sofiane Lagraa1287.48
Jérôme François217021.81