Self-adaptive distributed detection method of port scan

LIU Ting-hua,SONG Hua,DAI Yi-qi
DOI: https://doi.org/10.3969/j.issn.1000-7024.2006.09.003
2006-01-01
Abstract:Techniques of the port scan and its detection were introduced briefly.A new self-adaptive distributed detection method of port scan wasdesigned and implemented.By detecting anomalous packets and calculating the class's anomalysum value,it sets adynamic threshold combined with the network traffic,and then judges whether that is a scan.This method could detect slow scans,random scans and distributed scans effectively.And it could detect DDoS(distributed denial of service) attacks as well.
What problem does this paper attempt to address?