论文标题
扫描相关性 - 揭示分布式扫描活动
Scan Correlation -- Revealing distributed scan campaigns
论文作者
论文摘要
公共网络暴露于Internet端口扫描。攻击者搜索他们可以利用的脆弱服务。在大型扫描活动中,攻击者经常利用不同的机器进行分布式扫描,这阻碍了他们的检测,并可能伪装扫描活动的实际目标。在本文中,我们提出了一种相关算法,以检测扫描,确定它们之间的潜在关系并将其重新组装为更大的运动。我们评估了对现实世界互联网流量的方法,我们的结果表明,它可以根据其工具和意图来总结和表征独立和分布式扫描活动。
Public networks are exposed to port scans from the Internet. Attackers search for vulnerable services they can exploit. In large scan campaigns, attackers often utilize different machines to perform distributed scans, which impedes their detection and might also camouflage the actual goal of the scanning campaign. In this paper, we present a correlation algorithm to detect scans, identify potential relations among them, and reassemble them to larger campaigns. We evaluate our approach on real-world Internet traffic and our results indicate that it can summarize and characterize standalone and distributed scan campaigns based on their tools and intention.