Skip to main content

Collaborative Detection of Coordinated Port Scans

  • Conference paper
Distributed Computing and Networking (ICDCN 2013)

Part of the book series: Lecture Notes in Computer Science ((LNTCS,volume 7730))

Included in the following conference series:

Abstract

In this paper we analyze the coordinated port scan attack where a single adversary coordinates a Group of Attackers (GoA) in order to obtain information on a set of target networks. Such orchestration aims at avoiding Local Intrusion Detection Systems checks allowing each host of the GoA to send a very few number of probes to hosts of the target network. In order to detect this complex attack we propose a collaborative architecture where each target network deploys local sensors that send alarms to a collaborative layer. This, in turn, correlates this data with the aim of (i) identifying coordinated attacks while (ii) reducing false positive alarms and (iii) correctly separating GoAs that act concurrently on overlapping targets. The soundness of our approach is tested on real network traces. Tests show that collaboration among networks domains is mandatory to achieve accurate detection of coordinated attacks and sharp separation between GoAs that execute concurrent attacks on the same targets.

This is a preview of subscription content, log in via an institution to check access.

Access this chapter

Chapter
USD 29.95
Price excludes VAT (USA)
  • Available as PDF
  • Read on any device
  • Instant download
  • Own it forever
eBook
USD 39.99
Price excludes VAT (USA)
  • Available as PDF
  • Read on any device
  • Instant download
  • Own it forever
Softcover Book
USD 54.99
Price excludes VAT (USA)
  • Compact, lightweight edition
  • Dispatched in 3 to 5 business days
  • Free shipping worldwide - see info

Tax calculation will be finalised at checkout

Purchases are for personal use only

Institutional subscriptions

Preview

Unable to display preview. Download preview PDF.

Unable to display preview. Download preview PDF.

References

  1. Gates, C.: Coordinated scan detection. In: Proceedings of NDSS 2009 (2009)

    Google Scholar 

  2. Zhou, C.V., Leckie, C., Karunasekera, S.: A survey of coordinated attacks and collaborative intrusion detection. Computer and Security 29, 124–140 (2009-2010)

    Article  Google Scholar 

  3. Prais, M., Ribeiro, C.C.: Reactive grasp: An application to a matrix decomposition problem in tdma traffic assignment. INFORMS Journal on Computing 12, 164–176 (1998)

    Article  MathSciNet  Google Scholar 

  4. hybrid, Distributed Information Gathering (2011), http://www.phrack.org/issues.html?issue=55&id=9

  5. Staniford, S., Hoagland, J.A., Mcalerney, J.M.: Practical automated detection of stealthy portscans. Journal of Computer Security 10, 105–136 (2002)

    Google Scholar 

  6. Conti, G., Abdullah, K.: Passive visual fingerprinting of network attack tools. In: Proceedings of VizSEC/DMSEC 2004, pp. 45–54. ACM, New York (2004)

    Chapter  Google Scholar 

  7. Robertson, S., Siegel, E.V., Miller, M., Stolfo, S.J.: Surveillance detection in high bandwidth environments. In: Proceedings of DARPA DISCEX III, pp. 229–238. IEEE Press (2003)

    Google Scholar 

  8. DShield: Cooperative Network Security Community - Internet Security (2009), http://www.dshield.org/indexd.html/

  9. Yegneswaran, V., Barford, P., Ullrich, J.: Internet intrusions: global characteristics and prevalence. SIGMETRICS Perform. Eval. Rev. 31, 138–147 (2003)

    Article  Google Scholar 

  10. Baldoni, R., Chockler, G.: Collaborative Financial Infrastructure Protection. Springer (2012)

    Google Scholar 

  11. Baldoni, R., Luna, G.D., Querzoni, L.: Collaborative Detection of Coordinated Port Scans, MIDLAB 1/12 - University of Rome “La Sapienza” Tech. Rep. (2012), http://www.dis.uniroma1.it/~midlab/publications.php

  12. Newman, M.E.J.: Modularity and community structure in networks. Proceedings of the National Academy of Sciences 103(23), 8577–8582 (2006)

    Article  Google Scholar 

  13. Blondel, V., Guillaume, J., Lambiotte, R., Mech, E.: Fast unfolding of communities in large networks. J. Stat. Mech., 10008 (2008)

    Google Scholar 

  14. Jung (2011), http://jung.sourceforge.net/

  15. Esper (2011), http://esper.codehaus.org/

Download references

Author information

Authors and Affiliations

Authors

Editor information

Editors and Affiliations

Rights and permissions

Reprints and permissions

Copyright information

© 2013 Springer-Verlag Berlin Heidelberg

About this paper

Cite this paper

Baldoni, R., Di Luna, G.A., Querzoni, L. (2013). Collaborative Detection of Coordinated Port Scans. In: Frey, D., Raynal, M., Sarkar, S., Shyamasundar, R.K., Sinha, P. (eds) Distributed Computing and Networking. ICDCN 2013. Lecture Notes in Computer Science, vol 7730. Springer, Berlin, Heidelberg. https://doi.org/10.1007/978-3-642-35668-1_8

Download citation

  • DOI: https://doi.org/10.1007/978-3-642-35668-1_8

  • Publisher Name: Springer, Berlin, Heidelberg

  • Print ISBN: 978-3-642-35667-4

  • Online ISBN: 978-3-642-35668-1

  • eBook Packages: Computer ScienceComputer Science (R0)

Publish with us

Policies and ethics