Interactive visualization for network and port scan detection

  • Authors:
  • Chris Muelder;Kwan-Liu Ma;Tony Bartoletti

  • Affiliations:
  • University of California, Davis;University of California, Davis;Lawrence Livermore National Laboratory

  • Venue:
  • RAID'05 Proceedings of the 8th international conference on Recent Advances in Intrusion Detection
  • Year:
  • 2005

Quantified Score

Hi-index 0.00

Visualization

Abstract

Many times, network intrusion attempts begin with either a network scan, where a connection is attempted to every possible destination in a network, or a port scan, where a connection is attempted to each port on a given destination. Being able to detect such scans can help identify a more dangerous threat to a network. Several techniques exist to automatically detect scans, but these are mostly dependant on some threshold that an attacker could possibly avoid crossing. This paper presents a means to use visualization to detect scans interactively.