Ask HN: Ways to detect and prevent outgoing netscans?
I'm looking for ways to detect and actively prevent netscans. It is needed for a service that routes traffic like a VPN, but netscans, e.g. 175.123.54.0/24 whereas 175.123.54.1, 175.123.54.2, 175.123.54.3, .. are scanned for :5900 (VNC), :110 (pop3), .., shall be prevented and actively blocked.
My current solution includes hooking libpcap, having a LRU-ring for connections whereas each entry has a TTL of 5 seconds and consists of 1) first 24 bits of the IPs and 2) the target port (for detecting whether a subnet is scanned for a specific port, et al.). When a specific threshold is reached, e.g. subnet+port counter > 30 in lte 5 seconds, the subnet is banned. If the subnet is whitelisted, it will not be banned when a netscan was detected.
However - before I start over engineering that solution - is anyone aware of a solution that already implements preventing outgoing network scans?
Thanks