SANS Ad

Trends

The "Trend" is an attempt to put a number to the increase in activity for a given port. Right now, I am comparing the last 24 hours to the last 30 days. So if we see a rise in activity compared to the last 30 days, the trend is high.

The following formula is used to calculate the trend:
sqrt( (S-s)^2/s + (T-t)^2/t ) )
S: number of source IPs hitting this port last 24 hrs.
s: average number of source IPs hitten this port each day (last 30 days).
T/t: same for target IPs detecting scans on this port.

PortTrend
41126.93
200019.88
110117.18
26206.42
25086.35
24496.31
100015.08
320014.59
494013.75
66663.37
200003.22
83833.19
5533.06
80012.66
494002.6
514132.47
91512.35
30501.84
8081.79
99201.62
99781.47
10281.47
221.41
99881.29
18581.29
254021.29
18081.22
334341.09
80881.01
250.98
186400.91
97880.91
620000.87
10270.8
171530.79
23010.78
613880.68
389750.55
227360.49
670.23