Cited 1 time in
A Study on Risk Index to Analyze the Impact of Port Scan and to Detect Slow Port Scan in Network Intrusion Detection
| DC Field | Value | Language |
|---|---|---|
| dc.contributor.author | Park, Seongchul | - |
| dc.contributor.author | Kim, Juntae | - |
| dc.date.accessioned | 2024-08-08T01:01:51Z | - |
| dc.date.available | 2024-08-08T01:01:51Z | - |
| dc.date.issued | 2017-10 | - |
| dc.identifier.issn | 1936-6612 | - |
| dc.identifier.issn | 1936-7317 | - |
| dc.identifier.uri | https://scholarworks.dongguk.edu/handle/sw.dongguk/14768 | - |
| dc.description.abstract | Network port scan attack is a tool with which to identify any opened port in a system within the internal network. In most existing instances of the intrusion detection system, the port scan attack has been considered 'executed' against the source IP address for the outgoing packets whose count is higher than the threshold set according to the record of packets sent to the system or network per unit of time. That is, the risk level of a source IP address performing the network port scan attack has relied on the count of port scan attacks recorded by IDSs. However, the risk measurement solely based on the count of port scan attacks yields low port scan detection rates for the increased false negatives on slow port scan attacks. In this study, four different forms of the information are highlighted to accurately and comprehensively identify the network port scan attacks. A risk index quantifying such information through the Principal Component Analysis (PCA) is hereby proposed to express integrated risks on the port scan attacks. The detection using the risk index proposed through the experimentation demonstrates superior port scan detection rates than Snort. | - |
| dc.format.extent | 8 | - |
| dc.language | 영어 | - |
| dc.language.iso | ENG | - |
| dc.publisher | AMER SCIENTIFIC PUBLISHERS | - |
| dc.title | A Study on Risk Index to Analyze the Impact of Port Scan and to Detect Slow Port Scan in Network Intrusion Detection | - |
| dc.type | Article | - |
| dc.publisher.location | 미국 | - |
| dc.identifier.doi | 10.1166/asl.2017.10446 | - |
| dc.identifier.scopusid | 2-s2.0-85039423246 | - |
| dc.identifier.wosid | 000431743400226 | - |
| dc.identifier.bibliographicCitation | ADVANCED SCIENCE LETTERS, v.23, no.10, pp 10329 - 10336 | - |
| dc.citation.title | ADVANCED SCIENCE LETTERS | - |
| dc.citation.volume | 23 | - |
| dc.citation.number | 10 | - |
| dc.citation.startPage | 10329 | - |
| dc.citation.endPage | 10336 | - |
| dc.type.docType | Proceedings Paper | - |
| dc.description.isOpenAccess | N | - |
| dc.description.journalRegisteredClass | scopus | - |
| dc.relation.journalResearchArea | Science & Technology - Other Topics | - |
| dc.relation.journalWebOfScienceCategory | Multidisciplinary Sciences | - |
| dc.subject.keywordAuthor | Network Port Scan | - |
| dc.subject.keywordAuthor | Stealth Port Scan | - |
| dc.subject.keywordAuthor | Slow Port Scan | - |
| dc.subject.keywordAuthor | Network Intrusion Detection System | - |
| dc.subject.keywordAuthor | Risk Index | - |
| dc.subject.keywordAuthor | Principal Component Analysis | - |
Items in ScholarWorks are protected by copyright, with all rights reserved, unless otherwise indicated.
30, Pildong-ro 1-gil, Jung-gu, Seoul, 04620, Republic of Korea+82-2-2260-3114
Copyright(c) 2023 DONGGUK UNIVERSITY. ALL RIGHTS RESERVED.
Certain data included herein are derived from the © Web of Science of Clarivate Analytics. All rights reserved.
You may not copy or re-distribute this material in whole or in part without the prior written consent of Clarivate Analytics.
