Article (Scientific journals)
Deep mining port scans from darknet
Lagraa, Sofiane; Chen, Yutian; François, Jérôme
2019In International Journal of Network Management
Peer Reviewed verified by ORBi
 

Files


Full Text
document.pdf
Publisher postprint (1.33 MB)
Request a copy

All documents in ORBilu are protected by a user license.

Send to



Details



Keywords :
data mining; darknet; port scans; graph; text mining
Abstract :
[en] TCP/UDP port scanning or sweeping is one of the most common technique used 3 by attackers to discover accessible and potentially vulnerable hosts and applications. Although extracting and distinguishing different port scanning strategies is a challenging task, the identification of dependencies among probed ports is primordial for profiling attacker behaviors, with a final goal of better mitigating them. In this paper, we propose an approach that allows to track port scanning behavior patterns among multiple probed ports and identify intrinsic properties of observed group of orts. Our method is fully automated based on graph modeling and data mining techniques, including text mining. It provides to security analysts and operators relevant information about services that are jointly targeted by attackers. This is helpful to assess the strategy of the attacker by understanding the types of applications or environment he or she targets. We applied our method to data collected through a large Internet telescope (or darknet).
Disciplines :
Computer science
Author, co-author :
Lagraa, Sofiane ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT)
Chen, Yutian
François, Jérôme
External co-authors :
yes
Language :
English
Title :
Deep mining port scans from darknet
Publication date :
February 2019
Journal title :
International Journal of Network Management
ISSN :
1099-1190
Publisher :
John Wiley & Sons, Hoboken, United States - New Jersey
Peer reviewed :
Peer Reviewed verified by ORBi
Focus Area :
Computational Sciences
Name of the research project :
HuMa
Funders :
OTAN - Organisation du traité de l'Atlantique Nord [BE]
Bpifrance
Region Grand Est
Available on ORBilu :
since 20 February 2019

Statistics


Number of views
116 (4 by Unilu)
Number of downloads
2 (2 by Unilu)

Scopus citations®
 
12
Scopus citations®
without self-citations
10
OpenCitations
 
6
WoS citations
 
10

Bibliography


Similar publications



Contact ORBilu