Port Scan Detection via Dynamic Probability Updates
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current port scan detection methods are inadequate for large or transit networks, often resulting in high false positive rates due to reliance on specific network configurations and bi-directional traffic views, which are not readily available in these environments.
Innovation Solution
A system and method that assign a probability variable to network devices to determine port-scanning activities by analyzing transmission data across multiple time intervals, using thresholds for vertical and horizontal scanning patterns, and updating the probability variable based on sequential hypothesis testing, without requiring knowledge of network configurations or bi-directional traffic.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional port scan detection algorithms (SNORT, TRW) are applied in transit networks, then port scanning detection capability is provided, but false positive rate increases significantly
Solution Approach 1:
The patent transforms the detection approach by changing from fixed threshold parameters to dynamic probability parameters. Instead of using static thresholds that cause high false positives in transit networks, the system maintains a probability variable for each source IP that evolves over time based on observed behavior, adapting to the diverse traffic patterns of transit networks while maintaining detection accuracy
Solution Approach 2:
The system implements dynamic detection by continuously updating the probability variable for each source IP address based on sequential packet analysis. The detection threshold is not fixed but evolves dynamically as new packets are analyzed, allowing the system to adapt to changing traffic patterns and reduce false positives while maintaining reliable scanner detection
2Measurement precision
If detection algorithms require bi-directional traffic view and complete network configuration knowledge, then detection accuracy improves, but system complexity and information requirements increase
Solution Approach 1:
The patent extracts only the essential unidirectional traffic information needed for detection, eliminating the requirement for bi-directional traffic views and complete network configuration knowledge. By focusing solely on packets originating from source IPs and analyzing their destination patterns, the system achieves effective detection without the complexity of comprehensive network information
Solution Approach 2:
The detection system serves itself by using only the traffic data naturally available at the transit network boundary. It does not require external configuration information or bidirectional traffic data that would need to be collected from multiple sources, making the system self-sufficient and suitable for deployment in transit networks where such information is unavailable
Data Source
AI summary
A system and a method for detecting port scanning activities on a computer network. A probability variable is assigned to a device on a computer network. The probability variable indicates the probability that the device is conducting port-scanning activities. Data describing transmissions by the device during multiple intervals of time is accessed, and, for each of the time intervals, a determination is made concerning whether or not the device conducted port-scanning activities. Based on these determinations, the probability variable is updated for each of the time intervals.


