Research Article

A Hybrid Alarm Association Method Based on AP Clustering and Causality

Table 2

Types of honeypot data attacks.

Attack typeQuantity

Portmap-request-mountd111
Web-cgi10
Ping zeros51
SYN FIN scan47
DNS-version-query116
DNS-zone-transfer3989
Large-icmp286
Ping Microsoft Windows14
RPC-rpcinfo-query24
Spp_portscan838
SourcePortTraffic-53-tcp26
Ping Nmap 2.36BETA459
Socks-probe2627
Telnet-login-incorrect397
PING-ICMP time exceeded12
IDS118-MISC-traceroute ICMP2360
PING-ICMP destination unreachable709
IDS212–MISC1487
NAMED Iquery probe146
RPC-portmap-request-status67
MISC-Source Port Traffic 53 TCP60
SMTP-expn-root786
Portmap-request-mountd111