Invention Grant
- Patent Title: Method and apparatus for detecting port scans in a network
-
Application No.: US15954161Application Date: 2018-04-16
-
Publication No.: US10348749B2Publication Date: 2019-07-09
- Inventor: Wai Sum Lai , Andrew Egan , Wen-Jui Li
- Applicant: AT&T Intellectual Property I, L.P.
- Applicant Address: US GA Atlanta
- Assignee: AT&T Intellectual Property I, L.P.
- Current Assignee: AT&T Intellectual Property I, L.P.
- Current Assignee Address: US GA Atlanta
- Main IPC: H04L29/06
- IPC: H04L29/06 ; H04L12/26

Abstract:
A method and an apparatus for detecting a port scan in a network are disclosed. For example, the method extracts statistics from a message, detects the port scan for a source internet protocol address, determines whether a port scan record exists for the source internet protocol address, creates a port scan record for the source internet protocol address that is extracted when the port scan record does not exist, determines an elapsed time when the port scan record does exist, wherein the elapsed time is determined as a difference between the time stamp that is extracted and a recorded time stamp, sets the recorded time stamp to be the extracted time stamp when the elapsed time is less than an intra-scan time, and determines the port scan has ended for the source internet protocol address when the elapsed time is not less than the intra-scan time.
Public/Granted literature
- US20180234441A1 METHOD AND APPARATUS FOR DETECTING PORT SCANS IN A NETWORK Public/Granted day:2018-08-16
Information query