scanning activity seen lbnl scanning hosts seen lbnl
play

Scanning Activity Seen @ LBNL Scanning Hosts Seen @ LBNL Services - PowerPoint PPT Presentation

Scanning Activity Seen @ LBNL Scanning Hosts Seen @ LBNL Services Scanned Over Time Scans Per Scanner Hosts Scanned Per Scanner Ports Scanned Per Scanner Scanning Speed # Failed Conns Not Enough Info Failure Ratio Much More Distinctive


  1. Scanning Activity Seen @ LBNL

  2. Scanning Hosts Seen @ LBNL

  3. Services Scanned Over Time

  4. Scans Per Scanner

  5. Hosts Scanned Per Scanner

  6. Ports Scanned Per Scanner

  7. Scanning Speed

  8. # Failed Conn’s Not Enough Info

  9. Failure Ratio Much More Distinctive

  10. Real-Time Detection

  11. Expected Time Until Decision

  12. RB-SHT: Rate-Based Detection FCC’s interarrival times follow exponential dist. with • 1 mean (scanner) or (benign host). 1 1 1 � 0 � < 1 � � 0 1 T n : elapsed time until n FCC arrivals follows • n-Erlang distribution n ( ) ) � f n T n | H scanning � � = � 1 ( ) T n exp � � 1 � � 0 ( � n , T n � � ( ) f n T n | H benign � 0 � �

Download Presentation
Download Policy: The content available on the website is offered to you 'AS IS' for your personal information and use only. It cannot be commercialized, licensed, or distributed on other websites without prior consent from the author. To download a presentation, simply click this link. If you encounter any difficulties during the download process, it's possible that the publisher has removed the file from their server.

Recommend


More recommend