A Portscan Detection Method Based on Dempster-Shafer Theory of Evidence

LAI Hai-guang,XU Feng,HUANG Hao,XIE Jun-yuan
DOI: https://doi.org/10.3321/j.issn:0372-2112.2006.11.003
2006-01-01
Abstract:Portscan is used to figure out whether the target system's ports are open by trying to access these ports.It is usually the fist step of a sequence of intrusion actions.Portscan detection is an indispensable part of an intrusion detection system.However,there are only a few portscan detection methods nowadays.Moreover,they are not very accurate.In order to improve the accuracy of portscan detection,the data produced by two portscan detection methods is fused using DempsterShafer theory of evidence.One method is the ports distribution based portscan detection,which is very simple and has a pretty high detection ratio.The other is the sequential hypothesis testing based detection method,which sufficiently exploits the portscan's essential character.The experiment shows that the portscan detection method based on Dempster-Shafer theory of evidence is far more accurate than the one base on ports distribution or sequential hypothesis testing.
What problem does this paper attempt to address?