A Network Scanning Detection Method Based on TCP Flow State

  • Qiao Hong
  • , Tian Jianwei
  • , Ying Ying
  • , Tian Zheng
  • , Zhu Hongyu
  • , Li Shu

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

2 Scopus citations

Abstract

Network scanning is always the beginning action of network attack and recent detection methods are hard to detect distributed scanning behavior. This paper proposes a Network Scanning Detection algorithm based on Flow State (NSCDFS) to precisely detect both traditional scanning and distributed scanning. The algorithm divides the state of flows into 6 stages and set the state of each flow according to the flag value of its package. And based on the situation of flows' state from the same source IP address, the traditional scanning and the distributed scanning can be detected precisely. And the experimental result shows the algorithm works well in the high speed network.

Original languageEnglish
Title of host publicationProceedings - 2018 3rd International Conference on Smart City and Systems Engineering, ICSCSE 2018
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages419-422
Number of pages4
ISBN (Electronic)9781728113661
DOIs
StatePublished - 2 Jul 2018
Externally publishedYes
Event3rd International Conference on Smart City and Systems Engineering, ICSCSE 2018 - Xiamen, China
Duration: 29 Dec 201830 Dec 2018

Publication series

NameProceedings - 2018 3rd International Conference on Smart City and Systems Engineering, ICSCSE 2018

Conference

Conference3rd International Conference on Smart City and Systems Engineering, ICSCSE 2018
Country/TerritoryChina
CityXiamen
Period29/12/1830/12/18

Keywords

  • Distributed Scanning
  • Flow State
  • High Speed Network
  • Network Scanning

Fingerprint

Dive into the research topics of 'A Network Scanning Detection Method Based on TCP Flow State'. Together they form a unique fingerprint.

Cite this