A Privacy-Preserving Approach for Vulnerability Scanning Detection

Regano L.
Co-prime
;
2024-01-01

Abstract

This paper presents an approach leveraging machine learning techniques to monitor network traffic in search of vulnerability scanning activities. Indeed, attackers typically perform an initial reconnaissance phase to identify the vulnerabilities their target platforms expose, which they can abuse to perform cyberattacks. Classical network monitoring approaches have multiple limitations. Indeed, they are typically hindered by the presence of encrypted traffic, hamper user privacy resorting to Deep Packet Inspection (DPI), and cannot identify advanced scanning techniques such as slow scans. The research presented in this paper overcomes such limitations through machine learning classifiers that can detect vulnerability scans with flow-level granularity, employing statistical features evaluated on Layer 3 and 4 network packet headers. We demonstrate the feasibility of our approach training classifiers able to detect traffic originated by three well-known vulnerability scanning tools: OpenVAS, sqlmap, and Wapiti. The presented Proof-of-Concept classifiers are characterized by a high classification accuracy, with the best classifier reaching a balanced accuracy of 98%.
2024
Inglese
ITASEC 2024. Italian Conference on Cyber Security 2024. Proceedings of the 8th Italian Conference on Cyber Security (ITASEC 2024). Salerno, Italy, April 8-12, 2024
CEUR-WS
3731
13
https://ceur-ws.org/Vol-3731/
8th Italian Conference on Cyber Security, ITASEC 2024
Esperti anonimi
April 8-12, 2024
Salerno, Italia
scientifica
Intrusion Detection Systems (IDS); Intrusion Prevention Systems (IPS); Machine Learning (ML); Network Security; User Privacy; Vulnerability Scanning
4 Contributo in Atti di Convegno (Proceeding)::4.1 Contributo in Atti di convegno
Regano, L.; Canavese, D.; Mannella, L.
273
3
4.1 Contributo in Atti di convegno
open
info:eu-repo/semantics/conferencePaper
Files in This Item:
File Size Format  
paper44.pdf

open access

Type: versione editoriale
Size 269.96 kB
Format Adobe PDF
269.96 kB Adobe PDF View/Open

Items in DSpace are protected by copyright, with all rights reserved, unless otherwise indicated.

Questionnaire and social

Share on:
Impostazioni cookie