Detection of scanning attacks
A system for detecting network intrusions and other conditions in a network is described. The system includes a plurality of collector devices that are disposed to collect data and statistical information on packets that are sent between nodes on a network. An aggregator device is disposed to receive data and statistical information from the plurality of collector devices. The aggregator device produces a connection table that maps each node on the network to a record that stores information about traffic to or from the node. The aggregator runs processes that determine network events from aggregating of anomalies into network events.
1 . A method comprising:
detecting scans emanating from hosts;
analyzing records of scans to determine receivers of a scan and determine which of those receivers of scans that later became sources for a subsequent scan; and
reconstructing the path by which a worm spread based on the analyzed records; and
sending notification of the reconstructed path to a console.
2 . The method of claim 1 further comprising:
examining ports used by the worm to determine which services were exploited by the scan.
3 . The method of claim 2 further comprises:
analyzing scan anomalies for the sets of hosts scanned.
4 . The method of claim 3 further comprising:
determining that a worm has passed from a first host to a second host over a time period.
5 . The method of claim 1 further comprising:
determining ports that a worm spread through to identify vulnerable services in the hosts.
6 . The method of claim 1 wherein detecting scans further comprises:
executing a scan detection process to determine hosts that were targets of scans.
7 . A computer program product residing on a computer readable medium for detecting worm propagating comprising instructions for causing a computer to:
detect scans emanating from hosts;
analyze records of scans to determine receivers of a scan and determine which of those receivers of scans that later became sources for a subsequent scan; and
reconstruct the path by which a worm spread based on the analyzed records.
8 . The computer program product of claim 7 further comprising instructions to:
examine ports used by the worm to determine which services were exploited by the scan.
9 . The computer program product of claim 7 further comprises instructions to:
analyze scan anomalies for the sets of hosts scanned.
10 . The computer program product of claim 9 further comprising instructions to:
determine that a worm has passed from a first host to a second host over a time period.
11 . The computer program product of claim 7 further comprising instructions to:
determine ports that a worm spread through to identify vulnerable services in the hosts.
12 . The computer program product of claim 7 wherein instructions to detect scans further comprises instructions to:
execute a scan detection process to determine hosts that were targets of scans.
13 . Apparatus comprising:
a processing device;
a memory;
a computer readable medium storing a computer program product for detecting worm propagating comprising instructions for causing the processor device to:
detect scans emanating from hosts;
analyze records of scans to determine receivers of a scan and determine which of those receivers of scans that later became sources for a subsequent scan; and
reconstruct the path by which a worm spread based on the analyzed records.
14 . The apparatus of claim 13 further comprising instructions to:
examine ports used by the worm to determine which services were exploited by the scan.
15 . The apparatus of claim 13 further comprises instructions to:
analyze scan anomalies for the sets of hosts scanned.
16 . The apparatus of claim 13 further comprising instructions to:
determine that a worm has passed from a first host to a second host over a time period.