A Bitmap-Based Algorithm for Detecting Stealthy Superpoints
Zhimin Li, Weijiang Liu, Zhiyang Li, Jingxia Sun
Abstract
Zhimin Li, Weijiang Liu, Zhiyang Li, Jingxia Sun
Abstract
The host cardinality refers to the number of different peers that an Internet host communicates with. Stealthy superpoint is a host that its cardinality is between two thresholds during a measurement period. Detecting stealthy superpoints helps intrusion systems identify potential attackers. However, stealthy superpoints may perform scanning deliberately at a low rate, and they can easily evade the detection. The existing algorithm can not directly be used to detect them. This paper proposes an algorithm based on Bitmap which can detect stealthy superpoints. The algorithm includes online module and offline module. The online module consists of two submodules. One uses a bloom filter to filter the duplicate packets and store the source addresses. The other uses two-dimensional bit arrays to process packets. The offline estimates the cardinality. The theoretical analysis and experimental results show that our algorithm can precisely detect stealthy superpoints and estimate their cardinalities.
OpenAlex reports 4 citations for this work. Citation counts describe recorded attention and do not establish research quality.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
The host cardinality refers to the number of different peers that an Internet host communicates with. Stealthy superpoint is a host that its cardinality is between two thresholds during a measurement period. Detecting stealthy superpoints helps intrusion systems identify potential attackers. However, stealthy superpoints may perform scanning deliberately at a low rate, and they can easily evade the detection. The existing algorithm can not directly be used to detect them. This paper proposes an algorithm based on Bitmap which can detect stealthy superpoints. The algorithm includes online module and offline module. The online module consists of two submodules. One uses a bloom filter to filter the duplicate packets and store the source addresses. The other uses two-dimensional bit arrays to process packets. The offline estimates the cardinality. The theoretical analysis and experimental results show that our algorithm can precisely detect stealthy superpoints and estimate their cardinalities.
Key concepts: Bitmap, Bloom filter, Cardinality (data modeling), Computer science, Network packet, Filter (signal processing), Intrusion detection system, Host (biology)