# Detect Horizontal Port Scan

**URL:** <https://discuss.elastic.co/t/detect-horizontal-port-scan/272710>\
**Category:** Elastic Security\
**Created:** [May 11, 2021, 2:47pm UTC](https://discuss.elastic.co/t/detect-horizontal-port-scan/272710 "2021-05-11T14:47:19Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![pmorenosi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pmorenosi/32/85248_2.png) [@pmorenosi](https://discuss.elastic.co/u/pmorenosi)\
**Post date:** [May 11, 2021, 2:47pm UTC](https://discuss.elastic.co/t/detect-horizontal-port-scan/272710/1 "2021-05-11T14:47:19Z")

</div>

Hello everyone, From the logs that I have stored in Elasticsearch from a Firewall, I need to detect a type of attack called "Horizontal Port Scan" that is defined as follows:

Unique source IP address that has "N" different destinations and all go to the same port in a specified time.

Source IP ----\> N Destinations ---\> Same Port  
| ------------------------------ 2 hours ----------------- -------\>

the formulation of the question would be as follows:

What IP address has 20 different destination IP addresses to the same destination port in the last 2 hours?

the names of the fields are:

srcip (source IP / type IP), dstip (Destination IP / type IP) and port (port / type integer)

Thank you so much

---

<div class="post-metadata">

**Author:** ![Mike\_Paquette](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mike_paquette/32/119011_2.png) [@Mike\_Paquette](https://discuss.elastic.co/u/Mike_Paquette)\
**Post date:** [May 18, 2021, 11:23am UTC](https://discuss.elastic.co/t/detect-horizontal-port-scan/272710/2 "2021-05-18T11:23:09Z")

</div>

Hi @pmorenosi, welcome to our Community!

Glad to see you are trying out the detection rules within the Elastic SIEM/Security solution.

> Source IP ----\> N Destinations ---\> Same Port  
> | ------------------------------ 2 hours ----------------- -------\>  
> the formulation of the question would be as follows:  
> What IP address has 20 different destination IP addresses to the same destination port in the last 2 hours?

One idea is to create your own rule using the Threshold rule type in the 7.12 version. It has capabilities to do what you're looking for, like this.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/7/e/7eaac58b77e5789080df283fe79bbd166afb586c.jpeg)

> the names of the fields are:  
> srcip (source IP / type IP), dstip (Destination IP / type IP) and port (port / type integer)

You'll notice that my example above used different field names than yours. The fields I used are defined by [Elastic Common Schema](https://www.elastic.co/what-is/ecs) (ECS).

The Elastic SIEM/Security app, including its detection rules, signals, and detection alerts, requires your data to be indexed in an ECS-compliant format. [ECS](https://www.elastic.co/guide/en/ecs/current/ecs-reference.html) is an open source, community-developed schema that specifies field names and Elasticsearch data types for each field, and provides descriptions and example usage.

The easiest way to get your data in ECS-compliant format is to use an Elastic-supplied beat module, (e.g., [filebeat](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-modules-overview.html) or Elastic Agent integration), which will ingest and index your data in an ECS-compliant format. Elastic provides a growing list of these integrations that you can find on our [Integrations page](https://www.elastic.co/integrations?solution=security).

What kind of firewall logs are you working with? There are integrations already created for a number of firewalls such as Barracuda, Cisco, CheckPoint, Palo Alto, and more.

[General guidelines](https://www.elastic.co/guide/en/ecs/current/ecs-guidelines.html) for creating ECS-compliant data:

1. Each indexed document (e.g., your log, event, etc.) MUST have the `@timestamp` field.
2. Your index mapping template must specify the [Elasticsearch field data type](https://www.elastic.co/guide/en/elasticsearch/reference/current/mapping-types.html) for each field as defined by ECS. For example, your `@timestamp` field must be of the `date` field data type, etc.. This ensures that there will not be any mapping conflicts in your indices.
3. The original fields from your log/event SHOULD be copied/renamed/converted to the corresponding ECS-defined field name and data type.
4. Additional ECS fields, such as the [ECS Categorization fields](https://www.elastic.co/guide/en/ecs/current/ecs-category-field-values-reference.html) SHOULD be populated for each log/event, to allow proper inclusion of your data into dashboards and detection rules.

Here's a simple graphic that I created to help get this point across.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/1/3/134745457846e5b5ca6802e79e7bb2b08a09c7dc.jpeg)

Please let us know if this helps.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 15, 2021, 11:23am UTC](https://discuss.elastic.co/t/detect-horizontal-port-scan/272710/3 "2021-06-15T11:23:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
