Matches in SemOpenAlex for { <https://semopenalex.org/work/W2462522988> ?p ?o ?g. }
- W2462522988 abstract "Today’s society relies on computer networks. More and more data of vital importance are transmitted over them each day. Because of that, networks have become an interesting target for attackers, from ordinary criminals to foreign organizations and states. This has forced equipment providers and network administrators to make computer networks more robust. To this end, various countermeasures against cyber attacks are performed. One of the most commonly used ones is application of Intrusion Detection Systems (IDS). These systems are capable of classifying network traffic into several categories, according to the traffic features determined in advance. The basic classification performed by them is the classification in two classes – benign traffic and malicious traffic. The classification methods that IDS implement are different, but classic pattern/signature matching and statistical parametric decision making are used very often. According to the intrusion detection model, IDS are classified into two categories: misuse detection systems and anomaly detection systems. Misuse detection systems use a database of known attacks and report if they recognize signatures of known attacks in the incoming traffic. Anomaly detection systems define profiles of normal host/network behavior and report discrepancies from that. This thesis concentrates on methods of detection of special kind of reconnaissance activity in computer networks – so-called port scanning, which tries to determine what services are active on a target host. In addition, the scans are considered slow – this means that the time delay between scanning two ports is relatively long – from several minutes to several days. This kind of port scanning is in general harder to detect by IDS. The IDS of particular interest in this context is Bro – an open-source system that detects intrusions by semantic, highly stateful traffic analysis. This system also has advanced protocol detection capabilities. It can be configured to be either misuse or anomaly detection system, even a combination of both at the same time. As such, it has attracted much attention of the scientific community in the recent years. The goal of the thesis is to develop a method for slow port scanning detection with Bro and compare the capabilities of the new method with slow port scanning detection methods applied on other IDS, especially in the presence of noise. Our results shows that our modified version of scan.bro policy script, gave improved slow port scanning detection capabilities in Bro." @default.
- W2462522988 created "2016-07-22" @default.
- W2462522988 creator A5001500198 @default.
- W2462522988 date "2013-01-01" @default.
- W2462522988 modified "2023-09-24" @default.
- W2462522988 title "Slow Port Scanning with Bro" @default.
- W2462522988 cites W1448556541 @default.
- W2462522988 cites W1516506771 @default.
- W2462522988 cites W1531884035 @default.
- W2462522988 cites W1533194311 @default.
- W2462522988 cites W1564590057 @default.
- W2462522988 cites W1576185228 @default.
- W2462522988 cites W1581655543 @default.
- W2462522988 cites W1649901946 @default.
- W2462522988 cites W1674877186 @default.
- W2462522988 cites W177792351 @default.
- W2462522988 cites W191468885 @default.
- W2462522988 cites W1967151415 @default.
- W2462522988 cites W1979897473 @default.
- W2462522988 cites W1985987493 @default.
- W2462522988 cites W1986187640 @default.
- W2462522988 cites W1988918299 @default.
- W2462522988 cites W2001371112 @default.
- W2462522988 cites W2003116136 @default.
- W2462522988 cites W2009250465 @default.
- W2462522988 cites W2021200789 @default.
- W2462522988 cites W202500387 @default.
- W2462522988 cites W2032451229 @default.
- W2462522988 cites W2035156323 @default.
- W2462522988 cites W2036736235 @default.
- W2462522988 cites W2047073249 @default.
- W2462522988 cites W2104847067 @default.
- W2462522988 cites W2106061258 @default.
- W2462522988 cites W2107067193 @default.
- W2462522988 cites W2135251639 @default.
- W2462522988 cites W2143268355 @default.
- W2462522988 cites W2147029177 @default.
- W2462522988 cites W2150847526 @default.
- W2462522988 cites W2154492151 @default.
- W2462522988 cites W2158060559 @default.
- W2462522988 cites W2170196582 @default.
- W2462522988 cites W2174359540 @default.
- W2462522988 cites W2213017023 @default.
- W2462522988 cites W2261490266 @default.
- W2462522988 cites W2275530856 @default.
- W2462522988 cites W2301387700 @default.
- W2462522988 cites W2464606363 @default.
- W2462522988 cites W2534179324 @default.
- W2462522988 cites W2678934292 @default.
- W2462522988 cites W2992161509 @default.
- W2462522988 cites W34688585 @default.
- W2462522988 cites W2081642714 @default.
- W2462522988 hasPublicationYear "2013" @default.
- W2462522988 type Work @default.
- W2462522988 sameAs 2462522988 @default.
- W2462522988 citedByCount "1" @default.
- W2462522988 countsByYear W24625229882015 @default.
- W2462522988 crossrefType "dissertation" @default.
- W2462522988 hasAuthorship W2462522988A5001500198 @default.
- W2462522988 hasConcept C119599485 @default.
- W2462522988 hasConcept C124101348 @default.
- W2462522988 hasConcept C126831891 @default.
- W2462522988 hasConcept C127413603 @default.
- W2462522988 hasConcept C137524506 @default.
- W2462522988 hasConcept C154945302 @default.
- W2462522988 hasConcept C18903297 @default.
- W2462522988 hasConcept C2524010 @default.
- W2462522988 hasConcept C2776973144 @default.
- W2462522988 hasConcept C2779696439 @default.
- W2462522988 hasConcept C32802771 @default.
- W2462522988 hasConcept C33923547 @default.
- W2462522988 hasConcept C35525427 @default.
- W2462522988 hasConcept C38652104 @default.
- W2462522988 hasConcept C41008148 @default.
- W2462522988 hasConcept C739882 @default.
- W2462522988 hasConcept C86803240 @default.
- W2462522988 hasConceptScore W2462522988C119599485 @default.
- W2462522988 hasConceptScore W2462522988C124101348 @default.
- W2462522988 hasConceptScore W2462522988C126831891 @default.
- W2462522988 hasConceptScore W2462522988C127413603 @default.
- W2462522988 hasConceptScore W2462522988C137524506 @default.
- W2462522988 hasConceptScore W2462522988C154945302 @default.
- W2462522988 hasConceptScore W2462522988C18903297 @default.
- W2462522988 hasConceptScore W2462522988C2524010 @default.
- W2462522988 hasConceptScore W2462522988C2776973144 @default.
- W2462522988 hasConceptScore W2462522988C2779696439 @default.
- W2462522988 hasConceptScore W2462522988C32802771 @default.
- W2462522988 hasConceptScore W2462522988C33923547 @default.
- W2462522988 hasConceptScore W2462522988C35525427 @default.
- W2462522988 hasConceptScore W2462522988C38652104 @default.
- W2462522988 hasConceptScore W2462522988C41008148 @default.
- W2462522988 hasConceptScore W2462522988C739882 @default.
- W2462522988 hasConceptScore W2462522988C86803240 @default.
- W2462522988 hasLocation W24625229881 @default.
- W2462522988 hasOpenAccess W2462522988 @default.
- W2462522988 hasPrimaryLocation W24625229881 @default.
- W2462522988 hasRelatedWork W137954548 @default.
- W2462522988 hasRelatedWork W1876383431 @default.
- W2462522988 hasRelatedWork W2100588543 @default.
- W2462522988 hasRelatedWork W2188068387 @default.