학술논문

Automated detection of malicious reconnaissance to enhance network security
Document Type
Conference
Source
Proceedings. IEEE SoutheastCon, 2005. SoutheastCon SoutheastCon, 2005. Proceedings. IEEE. :450-454 2005
Subject
Communication, Networking and Broadcast Technologies
Components, Circuits, Devices and Systems
Computing and Processing
Engineered Materials, Dielectrics and Plasmas
Fields, Waves and Electromagnetics
Geoscience
Photonics and Electrooptics
Power, Energy and Industry Applications
Reconnaissance
Intrusion detection
Telecommunication traffic
Software testing
Protocols
Network topology
Computer science
Marine technology
Pattern matching
Monitoring
Language
ISSN
1091-0050
1558-058X
Abstract
Anomaly detection tools currently react to directed attacks during or shortly after they have occurred. Unfortunately, an attack that is detected after it has occurred is, in essence, a successful one. Advance warning of potential attacks could aid in their detection. Before an attack is launched the attacker often performs reconnaissance on the target host or network to learn its vulnerabilities. If malicious network reconnaissance can be detected and identified, it can serve as a warning of future attacks and may provide clues as to the identity of the attacker. This paper presents a novel technique for the automated detection of malicious network reconnaissance in a live network.