Effectiveness Evaluation of a Scan Detection Platform

MA Li-bo,ZHANG Jia,LI Xing
DOI: https://doi.org/10.3321/j.issn:0438-0479.2007.z2.021
2007-01-01
Abstract:A scan detection platform constructed by unused IP addresses will effectively improve detection accuracy and reduce false alarm.Before constructing a real scan detection platform,we need to evaluate the detection effectiveness of controlled monitoring addresses to predict the detecting tagets and determine the necessity of the platform deployment.To match these requirements,a new scan detection model based on network classification is presented.According to this model,we can evaluate the detection effectiveness of a scan detection platform which is used to detect random or local preference scanning sources and provide theory guidance for the platform construction and deployment.We use the Leurre'com Honeynet Project's distributed scan detection platform as a practical evaluation instance.Evaluation results show that the platform can effectively detect high speed random scanning sources like Slammer worm and local preference scanning sources whose average scanning rate is more than 2 scan connections per second.To low speed scanning sources,the detection effectiveness is poor.Statistics of real monitoring data and simulation results validate the veracity of evaluation results.
What problem does this paper attempt to address?