首页    期刊浏览 2024年09月21日 星期六
登录注册

文章基本信息

  • 标题:A Context Aware Scan Detection System
  • 作者:Joel Scanlan ; Jacky Hartnett
  • 期刊名称:International Journal of Computer Science and Network Security
  • 印刷版ISSN:1738-7906
  • 出版年度:2008
  • 卷号:8
  • 期号:1
  • 页码:75-84
  • 出版社:International Journal of Computer Science and Network Security
  • 摘要:It is well known that intrusion detection systems can make smarter decisions if the context of the traffic being observed is known. This paper examines whether an attack detection system, looking at traffic as it arrives at gateways or firewalls, can make smarter decisions if the context of attack patterns across a class of IP addresses is known. A system that detects and forestalls the continuation of both fast attacks and slow attacks across several IP addresses is described and the development of heuristics both to ban activity from hostile IP addresses and then lift these bans is illustrated. The system not only facilitates detection of methodical multiple gateway attacks, but also acts to defeat the attack before penetration can occur.
  • 关键词:Intrusion Detection; Scan Correlation; Prevention
Loading...
联系我们|关于我们|网站声明
国家哲学社会科学文献中心版权所有