A Learning Based Illegal Access Detection and Prevention System for Next Generation Network
基于学习的下一代网络非法接入检测与预防系统
基本信息
- 批准号:15300011
- 负责人:
- 金额:$ 3.97万
- 依托单位:
- 依托单位国家:日本
- 项目类别:Grant-in-Aid for Scientific Research (B)
- 财政年份:2003
- 资助国家:日本
- 起止时间:2003 至 2004
- 项目状态:已结题
- 来源:
- 关键词:
项目摘要
Recently, NIDS (Network-based Intrusion Detection System) has played an important role in Internet security system. However, the pattern matching technique used in NIDS is weak for new-type virus or unauthorized access, intentionally evasion act and is not expectable for next generation internet protocol IPv6 equipped with encryption. In this study, we propose a new access detection system which have learning function on subnetwork. Our goal is to develop next generation access detection system which include unknown illegal access detection structure, cooperate with NIDS and adapt to IPv6.In this research, we discussed about DoS (Denial of Service) attack that is difficult to detect in pattern matching technique and developed the system that learn and detect DoS attack This system exploit that the normal access follows the TCP congestion avoidance mechanism and will send test feedback to the source that being suspected of unauthorized access to decrease the transmission rate. By detecting the source's response, we can determine whether it is unauthorized access or not.Furthermore, we develop the software necessary for sharing information of detected unauthorized access among subnet NIDS and neighboring NIDS. This software makes it possible to block the unauthorized access extensively and we construct unauthorized access detection and extermination system combined with detection system. We had performed experiments over real network. As a result, we verified that detection-system is able to detect attack rapidly and accurately and we can realize high detection rate and low false negative rate.
近年来,基于网络的入侵检测系统(NIDS)在网络安全体系中扮演着重要的角色。然而,NIDS所采用的模式匹配技术对于新型病毒或非授权访问、故意规避行为的检测能力较弱,对于下一代IPv6加密网络也不适用。在本研究中,我们提出一个新的具有学习功能的子网路存取侦测系统。我们的目标是开发出一个包含未知非法访问检测结构、与NIDS协同工作、适应IPv6的下一代访问检测系统。我们讨论了DoS(拒绝服务)针对模式匹配技术中难以检测到的拒绝服务攻击,开发了学习和检测拒绝服务攻击的系统。该系统利用正常访问遵循TCP拥塞避免机制,并将发送测试向被怀疑未经授权访问的源反馈以降低传输速率。通过检测源的响应,我们可以确定它是否是未经授权的访问或没有。此外,我们开发了必要的软件,共享子网NIDS和邻居NIDS之间的检测到的未经授权的访问信息。该软件使得大范围的拦截非法访问成为可能,并结合检测系统构建了非法访问检测和查杀系统。我们在真实的网络上进行了实验。实验结果表明,该检测系统能够快速、准确地检测出攻击,实现了高检测率和低漏报率。
项目成果
期刊论文数量(16)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
加藤寧: "ユーザトラヒックパターンの特徴付けによるUDP Flooding抑制方式"2004年電子情報通信学会総合大会講演論文集. B-7-14. 223 (2004)
Yasushi Kato:“基于用户流量模式特征的 UDP 洪泛抑制方法”2004 年 IEICE 大会记录 B-7-14 (2004)。
- DOI:
- 发表时间:
- 期刊:
- 影响因子:0
- 作者:
- 通讯作者:
A Recursive, Explicit and Fair Method to Efficiently and Fairly Adjust TCP Windows in Satellite Networks
卫星网络中高效公平调整 TCP 窗口的递归、显式、公平方法
- DOI:
- 发表时间:2004
- 期刊:
- 影响因子:0
- 作者:Tarik Taleb;Tarik Taleb;Tarik Taleb;Tarik Taleb;Tarik Taleb;Tarik Taleb
- 通讯作者:Tarik Taleb
A Dummy Segment Based Bandwidth Probing Technique to Enhance the Performance of TCP over Heterogeneous Networks
基于虚拟段的带宽探测技术增强异构网络上的 TCP 性能
- DOI:
- 发表时间:2005
- 期刊:
- 影响因子:0
- 作者:A.SANO;K.NISHI;H.MIYANISHI;H.FUJIMOTO;Tarik Taleb
- 通讯作者:Tarik Taleb
On-Demand Media Streaming to Hybrid Wired/Wireless Networks over Quasi-Geo Stationary Satellite Systems
通过准地球静止卫星系统将点播媒体流传输到混合有线/无线网络
- DOI:
- 发表时间:2005
- 期刊:
- 影响因子:0
- 作者:T.Taleb;N.Kato;Y.Nemoto
- 通讯作者:Y.Nemoto
和泉勇治: "異常検知のためのネットワーク特徴量抽出法に関する一考察"2004年電子情報通信学会総合大会講演論文集. SB-4-1. S-27 (2004)
Yuji Izumi:“异常检测的网络特征提取方法的研究”2004 年 IEICE 大会 S-27 会议记录(2004 年)。
- DOI:
- 发表时间:
- 期刊:
- 影响因子:0
- 作者:
- 通讯作者:
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
KATO Nei其他文献
KATO Nei的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('KATO Nei', 18)}}的其他基金
Streaming Content Leakage Detection System for Encrypted Streams
加密流的流媒体内容泄漏检测系统
- 批准号:
22650010 - 财政年份:2010
- 资助金额:
$ 3.97万 - 项目类别:
Grant-in-Aid for Challenging Exploratory Research
Research on Next Generation Multi-Layered Satellite Network Highly Compatible with Internet Protocol
高度兼容互联网协议的下一代多层卫星网络研究
- 批准号:
20300021 - 财政年份:2008
- 资助金额:
$ 3.97万 - 项目类别:
Grant-in-Aid for Scientific Research (B)
Research of next generation LEO satellite networks which have high affinity with the Internet
与互联网高度亲和力的下一代LEO卫星网络研究
- 批准号:
17500030 - 财政年份:2005
- 资助金额:
$ 3.97万 - 项目类别:
Grant-in-Aid for Scientific Research (C)
A study of high sensitive illegal access detection system using distributed and cooperative scan detecting method.
采用分布式协同扫描检测方法的高灵敏非法访问检测系统研究
- 批准号:
13558038 - 财政年份:2001
- 资助金额:
$ 3.97万 - 项目类别:
Grant-in-Aid for Scientific Research (B)
Construction of knowledge-based next generation document
基于知识的下一代文档构建
- 批准号:
11558043 - 财政年份:1999
- 资助金额:
$ 3.97万 - 项目类别:
Grant-in-Aid for Scientific Research (B).
相似海外基金
Fair Game: valuing the bio-cultural heritage of fallow deer and their venison for food security, sustainable woodlands and biodiversity
公平游戏:重视小鹿及其鹿肉的生物文化遗产,以促进粮食安全、可持续林地和生物多样性
- 批准号:
AH/Z505675/1 - 财政年份:2024
- 资助金额:
$ 3.97万 - 项目类别:
Research Grant
CAREER: Verifying Security and Privacy of Distributed Applications
职业:验证分布式应用程序的安全性和隐私
- 批准号:
2338317 - 财政年份:2024
- 资助金额:
$ 3.97万 - 项目类别:
Continuing Grant
CAP: AI-Ready Institution Transforming Tomorrow's Research and Education with AI Focused on Health and Security (Jag-AI)
CAP:人工智能就绪机构通过专注于健康和安全的人工智能改变未来的研究和教育 (Jag-AI)
- 批准号:
2334243 - 财政年份:2024
- 资助金额:
$ 3.97万 - 项目类别:
Standard Grant
I-Corps: Networked Autonomous-humanoid Security Robot
I-Corps:网络化自主人形安全机器人
- 批准号:
2348931 - 财政年份:2024
- 资助金额:
$ 3.97万 - 项目类别:
Standard Grant
GNNs for Network Security (and Privacy) GRAPHS4SEC
用于网络安全(和隐私)的 GNN GRAPHS4SEC
- 批准号:
EP/Y036050/1 - 财政年份:2024
- 资助金额:
$ 3.97万 - 项目类别:
Research Grant
Hardware Security Module for secure delegated Quantum Cloud Computing
用于安全委托量子云计算的硬件安全模块
- 批准号:
EP/Z000564/1 - 财政年份:2024
- 资助金额:
$ 3.97万 - 项目类别:
Research Grant
Implementation Security of Quantum Cryptography
量子密码学的实现安全
- 批准号:
2907696 - 财政年份:2024
- 资助金额:
$ 3.97万 - 项目类别:
Studentship
Computational approach to security dilemma: understanding state rivalry through multilingual longitudinal analysis of foreign news
解决安全困境的计算方法:通过外国新闻的多语言纵向分析来理解国家竞争
- 批准号:
23K25490 - 财政年份:2024
- 资助金额:
$ 3.97万 - 项目类别:
Grant-in-Aid for Scientific Research (B)
CAREER: Foundational Principles for Harnessing Provenance Analytics for Advanced Enterprise Security
职业:利用来源分析实现高级企业安全的基本原则
- 批准号:
2339483 - 财政年份:2024
- 资助金额:
$ 3.97万 - 项目类别:
Continuing Grant
Scripps Center for Oceans and Human Health: advancing the science of marine contaminants and seafood security
斯克里普斯海洋与人类健康中心:推进海洋污染物和海鲜安全的科学
- 批准号:
2414798 - 财政年份:2024
- 资助金额:
$ 3.97万 - 项目类别:
Continuing Grant














{{item.name}}会员




