端口扫描是通过对目标系统端口试探性的访问来判断端口是否开放的行为,它往往是攻击者入侵行为的第一步.端口扫描检测是入侵监测系统不可缺少的一部分,而当前端口扫描的检测方法不多,并且准确性不高,为提高扫描检测的准确性,本文使用Dempster-Shafer证据理论对两种扫描检测方法产生的数据进行融合:一种是基于端口分布特征的扫描检测方法,该方法简单且具有较高的检测率;另一种是基于序列假设测试的扫描检测方法,该方法充分利用了端口扫描的本质特征,实验结果表明,同单独使用基于端口分布特征或序列假设测试的方法相比,这种基于Dempster-Shafer证据理论的扫描检测方法对端口扫描的检测准确得多。
Portscan is used to figure out whether the target system' s ports are open by trying to access these ports. It is usually the fist step of a sequence of intrusion actions. Portscan detection is an indispensable part of an intrusion detection system. However, there are only a few portscan detection methods nowadays. Moreover, they are not very accurate. In order to improve the accuracy of portscan detection, the data produced by two portscan detection methods is fused using Dempster-Shafer theory of evidence. One method is the ports distribution based portscan detection, which is very simple and has a pretty high detection ratio. The other is the sequential hypothesis testing based detection method, which sufficiently exploits the portscan' s essential character. The experiment shows that the portscan detection method based on Dempster-Shafer theory of evidence is far more accurate than the one base on ports distribution or sequential hypothesis testing.