Traffic analyzer for differentiating BitTorrent handshake failures from port-scans

Kamran Khan,Affan Syed,Ali Khayam
DOI: https://doi.org/10.48550/arXiv.1309.0276
2013-09-03
Abstract:This paper aims to improve the accuracy of port-scan detectors by analyzing traffic of BitTorrent hosts and differentiating their respective BitTorrent connection (attempts) from port-scans. It is shown that by looking at BitTorrent coordination traffic and modelling port-scanning behavior the number of BitTorrent-related false positives can be reduced by 80% without any loss of IDS accuracy.
Networking and Internet Architecture
What problem does this paper attempt to address?