Scanning Activity Seen @ LBNL Scanning Hosts Seen @ LBNL Services - - PowerPoint PPT Presentation

scanning activity seen lbnl scanning hosts seen lbnl
SMART_READER_LITE
LIVE PREVIEW

Scanning Activity Seen @ LBNL Scanning Hosts Seen @ LBNL Services - - PowerPoint PPT Presentation

Scanning Activity Seen @ LBNL Scanning Hosts Seen @ LBNL Services Scanned Over Time Scans Per Scanner Hosts Scanned Per Scanner Ports Scanned Per Scanner Scanning Speed # Failed Conns Not Enough Info Failure Ratio Much More Distinctive


slide-1
SLIDE 1

Scanning Activity Seen @ LBNL

slide-2
SLIDE 2

Scanning Hosts Seen @ LBNL

slide-3
SLIDE 3

Services Scanned Over Time

slide-4
SLIDE 4

Scans Per Scanner

slide-5
SLIDE 5

Hosts Scanned Per Scanner

slide-6
SLIDE 6

Ports Scanned Per Scanner

slide-7
SLIDE 7

Scanning Speed

slide-8
SLIDE 8

# Failed Conn’s Not Enough Info

slide-9
SLIDE 9

Failure Ratio Much More Distinctive

slide-10
SLIDE 10

Real-Time Detection

slide-11
SLIDE 11

Expected Time Until Decision

slide-12
SLIDE 12

RB-SHT: Rate-Based Detection

n,Tn

( ) fn Tn | Hscanning

( )

fn Tn | Hbenign

( )

= 1

  • n

exp 10

( )Tn

  • FCC’s interarrival times follow exponential dist. with

mean (scanner) or (benign host).

  • Tn : elapsed time until n FCC arrivals follows

n-Erlang distribution 1

  • 1

1

1

  • 1

< 1