摘要
简要介绍了端口扫描技术及其检测技术,设计并实现了一种自适应的分布式端口扫描检测方法。该方法通过对异常包的检测及分类计算异常值的总和,并结合网络流量,设定动态阈值,然后判断出扫描。这种方法能有效地检测到慢速扫描、随机化扫描和分布式扫描,并能检测出分布式拒绝服务(DDoS)攻击。
Techniques of the port scan and its detection were introduced briefly. A new self-adaptive distributed detection method of port scan was designed and implemented. By detecting anomalous packets and calculating the class's anomaly sum value, it sets a dynamic threshold combined with the network traffic, and then judges whether that is a scan. This method could detect slow scans, random scans and distributed scans effectively. And it could detect DDoS (distributed denial of service) attacks as well.
出处
《计算机工程与设计》
CSCD
北大核心
2006年第9期1521-1523,共3页
Computer Engineering and Design
基金
国家自然科学基金项目(90104032)
关键词
端口扫描
端口扫描检测
分布式端口扫描检测
异常包
分布式拒绝服务
port scan
port scan detection
distributed detection of port scan
anomalous packet
distributed denial of service (DDoS)