Follow Us

Port scans don't always precede hacks

Latest research turns accepted wisdom on its head.

Port scans may not be a pre-cursor to hacking efforts, according to conventional wisdom, reports the University of Maryland's engineering school.

An analysis of quantitative attack data gathered by the university over a two-month period showed that port scans precede attacks only about five percent of the time, said Michel Cukier, a professor in the Centre for Risk and Reliability. In fact, more than half of all attacks aren't preceded by a scan of any kind, Cukier said.

"There's been a lot of discussion in the security community about whether a port scan portends an attack or not," he said. "The goal of the research is to find a link between port scans and an attack."

Port scans are generally believed to be used by attackers to discover open or closed ports and unused network services to exploit. Large increases in scans against a particular port have long been viewed as a signal of impending attacks against that port.

But the evidence gathered from 48 days' worth of data collected from two "honeypot" computers used in the study suggest otherwise, Cukier said.

Only 28 out of 760 IP addresses that were tied to attacks against the university's computers had launched a port scan, Cukier said. In contrast, 381 of the IP addresses launched attacks without any previous port-scanning activity.

The study did find that 21 percent of the attacks were preceded by vulnerability scans, which are used by hackers to look for specific vulnerabilities on network-attached computers, Cukier said.

The numbers suggest that only when port scans are combined with vulnerability-scanning activity is there a reasonably good chance of a follow-up attack, he said.

During the study, more than 22,000 connections to the two honeypot computers were analysed. Scripts were developed to categorise the data into port scans, vulnerability scans, Internet Control Message Protocol scans and attacks.

For the analysis, port scans were defined as connections involving fewer than five data packets and vulnerability scans as those connections with five to 12 packets. Connections with more than 12 packets were classified as attacks.

Johannes Ullrich, chief technology officer at the SANS Institute 's Internet Storm Center, said that while the design and development of the testbed used for the research appears to be valid, the analysis is too simplistic.

Rather than counting the number of packets in a connection, it's far more important to look at the content when classifying a connection as a port scan or an attack, Ullrich said.

Often, attacks such as the SQL Slammer worm, which hit in 2003, can be as small as one data packet, he said. A lot of the automated attacks that take place combine port and vulnerability scans and exploit code, according to Ullrich.

As a result, much of what researchers counted as port scans may have actually been attacks, said Ullrich, whose Bethesda, Md.-based organization provides Internet threat-monitoring services.






Send to a friend

Email this article to a friend or colleague:

PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.

Techworld White Papers

State of software security report volume 4

If your business has anything worth protecting, be it money, intellectual property or a trusted...

Download Whitepaper

New threats demand innovative responses

Financial institutions in the UK remain susceptible to further systemic problems, as challenging...

Download Whitepaper

Delivering a competitive advantage through IT

IT organisations share a common mission; to optimise investments and streamline operations to...

Download Whitepaper

6 tips to mobilise your existing ERP

Enterprise mobile users throughout the global business community will number 1.19 billion by...

Download Whitepaper

Techworld UK - Technology - Business

Techworld Awards

Techworld Awards Winners 2011


Learn who the winners of this year's Techworld Awards are. Video footage coming soon...

Find out more
Techworld Mobile Site

Access Techworld's content on the move

Get the latest news, product reviews and downloads on your mobile device with Techworld's mobile site.

Find out more...

Site Map

* *