Scan detection in ip networks using sequential hypothesis testing
Sergei Vsevolodovich Bredikhin, Viktor Igorevich Kostin, Natalya Grigoryevna Shcherbakova

Institute of Computational Mathematics and Mathematical Geophysics SB RAS

UDC code: 004.415.532

The approaches to scan detection in IP networks are considered in the first part of the article. The information on the base methods used in the known intrusion detection systems Snort and Bro, and also applying of statistical models for anomalous traffic diagnostic is introduсed. The special attention is given to a method of the sequential analysis and to models that use this method for scan detection. The algorithm for scan detection in IP networks is introduced in the second part of the article. The algorithm is based on the method of sequential hypothesis testing by A. Wald. The results of algorithm approbation in the Internet SB RAS environement are given. The performance evaluations are presented and algorithm capabilities depending on the parameters values are investigated

Key Words
algorithm, models TRW and TAPS, sequential hypothesis testing by A. Wald, statistical methods, base systems Snort and Bro, address / port scanning, IP-based networks

How to cite:
Bredikhin S. V., Kostin V. I., Shcherbakova N. G. Scan detection in ip networks using sequential hypothesis testing // Vestnik NSU Series: Information Technologies. - 2009. - Volume 07, Issue No 4. - P. 15-35. - ISSN 1818-7900. (in Russian).

Full Text in Russian

Available in PDF

DSpace handle

