Scanning Activity Seen @ LBNL
Scanning Hosts Seen @ LBNL
Services Scanned Over Time
Scans Per Scanner
Hosts Scanned Per Scanner
Ports Scanned Per Scanner
Scanning Speed
# Failed Conn’s Not Enough Info
Failure Ratio Much More Distinctive
Real-Time Detection
Expected Time Until Decision
RB-SHT: Rate-Based Detection FCC’s interarrival times follow exponential dist. with • 1 mean (scanner) or (benign host). 1 1 1 � 0 � < 1 � � 0 1 T n : elapsed time until n FCC arrivals follows • n-Erlang distribution n ( ) ) � f n T n | H scanning � � = � 1 ( ) T n exp � � 1 � � 0 ( � n , T n � � ( ) f n T n | H benign � 0 � �
Recommend
More recommend