Combating TCP Port Scan Attacks Using Sequential Neural Networks
Title | Combating TCP Port Scan Attacks Using Sequential Neural Networks |
Publication Type | Conference Paper |
Year of Publication | 2020 |
Authors | Hartpence, B., Kwasinski, A. |
Conference Name | 2020 International Conference on Computing, Networking and Communications (ICNC) |
Date Published | Feb. 2020 |
Publisher | IEEE |
ISBN Number | 978-1-7281-4905-9 |
Keywords | attack reconnaissance tool, classification, Communication networks, complex TCP classes, computer network security, general packetized traffic, learning (artificial intelligence), Network reconnaissance, neural nets, Neural networks, NMAP scan pcap files, port scans, pubcrawl, resilience, Resiliency, Scalability, sequential neural networks, TCP datagrams, TCP packet, TCP port scan attacks, telecommunication traffic, transport protocols |
Abstract | Port scans are a persistent problem on contemporary communication networks. Typically used as an attack reconnaissance tool, they can also create problems with application performance and throughput. This paper describes an architecture that deploys sequential neural networks (NNs) to classify packets, separate TCP datagrams, determine the type of TCP packet and detect port scans. Sequential networks allow this lengthy task to learn from the current environment and to be broken up into component parts. Following classification, analysis is performed in order to discover scan attempts. We show that neural networks can be used to successfully classify general packetized traffic at recognition rates above 99% and more complex TCP classes at rates that are also above 99%. We demonstrate that this specific communications task can successfully be broken up into smaller work loads. When tested against actual NMAP scan pcap files, this model successfully discovers open ports and the scan attempts with the same high percentage and low false positives. |
URL | https://ieeexplore.ieee.org/document/9049730 |
DOI | 10.1109/ICNC47757.2020.9049730 |
Citation Key | hartpence_combating_2020 |
- port scans
- transport protocols
- telecommunication traffic
- TCP port scan attacks
- TCP packet
- TCP datagrams
- sequential neural networks
- Scalability
- Resiliency
- resilience
- pubcrawl
- attack reconnaissance tool
- NMAP scan pcap files
- Neural networks
- neural nets
- Network reconnaissance
- learning (artificial intelligence)
- general packetized traffic
- computer network security
- complex TCP classes
- Communication networks
- classification