In the dynamic landscape of cybersecurity, detecting reconnaissance attacks at an early stage is critical in preventing potential security breaches. This paper presents a comprehensive approach to identify reconnaissance activities through a signature-based detection system. The system employs a combination of network and Windows OS system information gathering techniques to discern patterns indicative of reconnaissance attacks. In order to obtain relevant data, methods including port scanning, packet sniffing, DNS analysis, and WHOIS lookups are laid out in the section on network information collection. In a similar vein, the Windows system information collection section describes how Registry analysis and Windows Management Instrumentation (WMI) are used to collect system-related data. The development and use of detection mechanisms based on signatures creation and comparison forms the basis of the proposed system. Signatures are carefully constructed patterns that represent characteristics of reconnaissance activities. By using signature-based techniques, this approach provides a comprehensive strategy for detecting reconnaissance attacks and identifying threats. The study also showed a noteworthy advancement in improving cybersecurity procedures.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

A Novel Signature Based Reconnaissance Attack Detection and Threat Identification System

  • T. Raj Kumar,
  • M. C. Aswathy,
  • N. V. Sobhana

摘要

In the dynamic landscape of cybersecurity, detecting reconnaissance attacks at an early stage is critical in preventing potential security breaches. This paper presents a comprehensive approach to identify reconnaissance activities through a signature-based detection system. The system employs a combination of network and Windows OS system information gathering techniques to discern patterns indicative of reconnaissance attacks. In order to obtain relevant data, methods including port scanning, packet sniffing, DNS analysis, and WHOIS lookups are laid out in the section on network information collection. In a similar vein, the Windows system information collection section describes how Registry analysis and Windows Management Instrumentation (WMI) are used to collect system-related data. The development and use of detection mechanisms based on signatures creation and comparison forms the basis of the proposed system. Signatures are carefully constructed patterns that represent characteristics of reconnaissance activities. By using signature-based techniques, this approach provides a comprehensive strategy for detecting reconnaissance attacks and identifying threats. The study also showed a noteworthy advancement in improving cybersecurity procedures.