
摘 要
关键词:大数据分析 网络安全 扫描 告警
Network security event warning based on big data analysis
The precursor to many cyber attacks is often reconnaissance, often called scanning.This paper formalizes the problem of scanning detection into a data mining problem.Based on the data processing capacity of iMAP platform, this paper establishes the scanning behavior model and writes the recognition rules by taking advantage of the characteristics of sending syn packets and traffic anomalies to the destination IP from time to time. [资料来源:https://www.doc163.com]
For the rules designed in this paper, its practical significance is not to accurately determine whether each stream is generated by scanning behavior.However, through big data analysis, when the behavior of the attacker reaches a certain scale, it will pose a certain threat to the deployed network, and warn the manager to timely deal with and solve the problem.Among them, the scanning of the internal network address by the external network mainly focuses on whether the attack traffic will affect the normal communication of the internal network.Warning internal network address external network scanning is to remind the administrator whether the internal network address has been in the virus or has been under the control of the attacker.
This paper tests the real data of the designed rules and tests the test results.The results show that the proposed rules are effective and have some practical significance in alerting the scanning behavior.
Key Words: Big Data Analysis; Network Security; Scan; Alarm

目 录
第一章 引言………………………………………………………………………1
1.1 课题来源及意义……………………………………………………………1
1.2 国内外的研究和发展现状…………………………………………………2
第二章 端口扫描…………………………………………………………………3 [资料来源:http://Doc163.com]
2.1 定义…………………………………………………………………………3
2.2 端口扫描的分类……………………………………………………………3
2.3 扫描行为特征………………………………………………………………6
2.3.2 TCP状态分析………………………………………………………7
2.3.3 TCP状态值…………………………………………………………9
第三章 规则设计………………………………………………………………11
3.1 平台介绍…………………………………………………………………11
3.2 外网扫描规则……………………………………………………………12
3.3 内网扫描规则……………………………………………………………15 [资料来源:Doc163.com]
3.4 章节总结…………………………………………………………………19
第四章 实验检测………………………………………………………………20
4.1 内网发起的扫描…………………………………………………………20
4.1.1 SYN扫描行为………………………………………………………20
4.1.2 针对固定端口的扫描………………………………………………23
4.1.3 针对固定IP的扫描………………………………………………24
4.2 外网向内网发起的扫描…………………………………………………26
4.3 章节总结…………………………………………………………………29
第五章 总结与展望…………………………………………………………30
致谢………………………………………………………………………………32 [版权所有:http://DOC163.com]