Open Access Open Access  Restricted Access Subscription Access

Connection Failure Message-based Approach for Detecting Sequential and Random Tcp Scanning


Affiliations
1 National Advanced IPv6 Centre (NAv6), Universiti Sains, Malaysia
2 Universiti Malaysia Perlis 02600 UNIMAP, Perlis, Malaysia
 

Network scanning is considered the first step for attackers to gain access to a targeted network. Attackers will blindly scan the network without any prior knowledge about the active service or host in the target network. Such blind scan will generate a high ratio of connection failure messages that come in the form of Internet Common Message Protocol type3 code1 (host unreachable) and TCP-RST packets. This paper proposes an approach for TCP random and sequential scanning detection on the basis of connection failure messages.

Keywords

Connection Failure, Network Scanning, TCP Random Scanning, TCP Sequential Scanning
User

Abstract Views: 200

PDF Views: 0




  • Connection Failure Message-based Approach for Detecting Sequential and Random Tcp Scanning

Abstract Views: 200  |  PDF Views: 0

Authors

Mohammed Anbar
National Advanced IPv6 Centre (NAv6), Universiti Sains, Malaysia
Sureswaran Ramadass
National Advanced IPv6 Centre (NAv6), Universiti Sains, Malaysia
Selvakumar Manickam
National Advanced IPv6 Centre (NAv6), Universiti Sains, Malaysia
Alhamza Al-Wardi
Universiti Malaysia Perlis 02600 UNIMAP, Perlis, Malaysia

Abstract


Network scanning is considered the first step for attackers to gain access to a targeted network. Attackers will blindly scan the network without any prior knowledge about the active service or host in the target network. Such blind scan will generate a high ratio of connection failure messages that come in the form of Internet Common Message Protocol type3 code1 (host unreachable) and TCP-RST packets. This paper proposes an approach for TCP random and sequential scanning detection on the basis of connection failure messages.

Keywords


Connection Failure, Network Scanning, TCP Random Scanning, TCP Sequential Scanning



DOI: https://doi.org/10.17485/ijst%2F2014%2Fv7i5%2F54104