Detection of port scan is an important component in a network intrusion detection and prevention system. Traditional statistical methods can be easily evaded by stealthy scans and are prone to DoS attacks. This paper ...Detection of port scan is an important component in a network intrusion detection and prevention system. Traditional statistical methods can be easily evaded by stealthy scans and are prone to DoS attacks. This paper presents a new mechanism termed PSD(port scan detection), which is based on TCP packet anomaly evaluation. By learning the port distribution and flags of TCP packets arriving at the protected hosts, PSD can compute the anomaly score of each packet and effectively detect port scans including slow scans and stealthy scans. Experiments show that PSD has high detection accuracy and low detection latency.展开更多
Anomaly detection is now very important in the network because the increasing use of the internet and security of a network or user is a main concern of any network administrator. As the use of the internet increases,...Anomaly detection is now very important in the network because the increasing use of the internet and security of a network or user is a main concern of any network administrator. As the use of the internet increases, so the chances of having a threat or attack in the network are also increasing day by day and traffic in the network is also increasing. It is very difficult to analyse all the traffic data in network for finding the anomaly in the network and sampling provides a way to analyse the anomalies in network with less traffic data. In this paper, we propose a port scan detection approach called CPST uses connection status and pattern of the connections to detect a particular source is scanner or benign host. We also show that this approach works efficiently under different sampling methods.展开更多
针对城市信息模型(city information modeling,CIM)平台中Docker容器依赖顺序难以确定以及现有启动机制无法确保所有容器顺利运行的问题,提出了一种Docker容器编排优化方法,创新的应用于CIM平台。该方法通过引入基于深度优先搜索的拓扑...针对城市信息模型(city information modeling,CIM)平台中Docker容器依赖顺序难以确定以及现有启动机制无法确保所有容器顺利运行的问题,提出了一种Docker容器编排优化方法,创新的应用于CIM平台。该方法通过引入基于深度优先搜索的拓扑排序,并定制启发式比较器,实现了对容器的精确排序。同时,结合Docker Compose和端口扫描技术进行容器编排,解决了因容器未初始化导致的启动失败问题。在沣西新城CIM平台的应用表明,引入此方案后容器顺序合理,系统成功运行率超过93%,比传统方法提高了约20%。该方法增强了CIM平台容器编排的健壮性,为复杂系统的容器管理提供了参考依据。展开更多
文摘Detection of port scan is an important component in a network intrusion detection and prevention system. Traditional statistical methods can be easily evaded by stealthy scans and are prone to DoS attacks. This paper presents a new mechanism termed PSD(port scan detection), which is based on TCP packet anomaly evaluation. By learning the port distribution and flags of TCP packets arriving at the protected hosts, PSD can compute the anomaly score of each packet and effectively detect port scans including slow scans and stealthy scans. Experiments show that PSD has high detection accuracy and low detection latency.
文摘Anomaly detection is now very important in the network because the increasing use of the internet and security of a network or user is a main concern of any network administrator. As the use of the internet increases, so the chances of having a threat or attack in the network are also increasing day by day and traffic in the network is also increasing. It is very difficult to analyse all the traffic data in network for finding the anomaly in the network and sampling provides a way to analyse the anomalies in network with less traffic data. In this paper, we propose a port scan detection approach called CPST uses connection status and pattern of the connections to detect a particular source is scanner or benign host. We also show that this approach works efficiently under different sampling methods.
文摘针对城市信息模型(city information modeling,CIM)平台中Docker容器依赖顺序难以确定以及现有启动机制无法确保所有容器顺利运行的问题,提出了一种Docker容器编排优化方法,创新的应用于CIM平台。该方法通过引入基于深度优先搜索的拓扑排序,并定制启发式比较器,实现了对容器的精确排序。同时,结合Docker Compose和端口扫描技术进行容器编排,解决了因容器未初始化导致的启动失败问题。在沣西新城CIM平台的应用表明,引入此方案后容器顺序合理,系统成功运行率超过93%,比传统方法提高了约20%。该方法增强了CIM平台容器编排的健壮性,为复杂系统的容器管理提供了参考依据。