کد مقاله کد نشریه سال انتشار مقاله انگلیسی نسخه تمام متن
450250 693875 2009 11 صفحه PDF دانلود رایگان
عنوان انگلیسی مقاله ISI
FDF: Frequency detection-based filtering of scanning worms
موضوعات مرتبط
مهندسی و علوم پایه مهندسی کامپیوتر شبکه های کامپیوتری و ارتباطات
پیش نمایش صفحه اول مقاله
FDF: Frequency detection-based filtering of scanning worms
چکیده انگلیسی

In this paper, we propose a simple algorithm for detecting scanning worms with high detection rate and low false positive rate. The novelty of our algorithm is inspecting the frequency characteristic of scanning worms instead of counting the number of suspicious connections or packets from a monitored network. Its low complexity allows it to be used on any network-based intrusion detection system as a real-time detection module for high-speed networks.Our algorithm need not be adjusted to network status because its parameters depend on application types, which are generally and widely used in any networks such as web and P2P services. By using real traces, we evaluate the performance of our algorithm and compare it with that of SNORT. The results confirm that our algorithm outperforms SNORT with respect to detection rate and false positive rate.

ناشر
Database: Elsevier - ScienceDirect (ساینس دایرکت)
Journal: Computer Communications - Volume 32, Issue 5, 27 March 2009, Pages 847–857
نویسندگان
, , ,