TY - GEN
T1 - Scan detection
T2 - Sixth SIAM International Conference on Data Mining
AU - Simon, Gyorgy J
AU - Xiong, Hui
AU - Eilertson, Eric
AU - Kumar, Vipin
N1 - Copyright:
Copyright 2020 Elsevier B.V., All rights reserved.
PY - 2006
Y1 - 2006
N2 - A precursor to many attacks on networks is often a reconnaissance operation, more commonly referred to as a scan. Despite the vast amount of attention focused on methods for scan detection, the state-of-the-art methods suffer from high rate of false alarms and low rate of scan detection. In this paper, we formalize the problem of scan detection as a data mining problem. We show how the network traffic data sets can be converted into a data set that is appropriate for running off-the-shelf classifiers on. Our method successfully demonstrates that data mining models can encapsulate expert knowledge to create an adaptable algorithm that can substantially outperform state-of-the-art methods for scan detection in both coverage and precision.
AB - A precursor to many attacks on networks is often a reconnaissance operation, more commonly referred to as a scan. Despite the vast amount of attention focused on methods for scan detection, the state-of-the-art methods suffer from high rate of false alarms and low rate of scan detection. In this paper, we formalize the problem of scan detection as a data mining problem. We show how the network traffic data sets can be converted into a data set that is appropriate for running off-the-shelf classifiers on. Our method successfully demonstrates that data mining models can encapsulate expert knowledge to create an adaptable algorithm that can substantially outperform state-of-the-art methods for scan detection in both coverage and precision.
UR - http://www.scopus.com/inward/record.url?scp=33745474966&partnerID=8YFLogxK
UR - http://www.scopus.com/inward/citedby.url?scp=33745474966&partnerID=8YFLogxK
U2 - 10.1137/1.9781611972764.11
DO - 10.1137/1.9781611972764.11
M3 - Conference contribution
AN - SCOPUS:33745474966
SN - 089871611X
SN - 9780898716115
T3 - Proceedings of the Sixth SIAM International Conference on Data Mining
SP - 118
EP - 129
BT - Proceedings of the Sixth SIAM International Conference on Data Mining
PB - Society for Industrial and Applied Mathematics
Y2 - 20 April 2006 through 22 April 2006
ER -