A Learning Based Illegal Access Detection and Prevention System for Next Generation Network
A Learning Based Illegal Access Detection and Prevention System for Next Generation Network
批准号:
15300011
负责人:
KATO Nei
金额:
$3.97万
依托单位:
依托单位国家:
日本
项目类别:
Grant-in-Aid for Scientific Research (B)
财政年份:
2003
资助国家:
日本
项目状态:
已结题
起止时间:
2003 至 2004
中文摘要
近年来,基于网络的入侵检测系统在网络安全系统中发挥了重要作用。然而,网络入侵检测系统中使用的模式匹配技术对新型病毒或未经授权的访问、故意规避行为的能力较弱,对于配备加密的下一代互联网协议IPv6来说是不可取的。在本研究中,我们提出了一种新的具有子网络学习功能的访问检测系统。我们的目标是开发下一代接入检测系统,包括未知的非法访问检测结构,与网络入侵检测系统合作,适应IPv6。在本研究中,我们讨论了模式匹配技术中难以检测到的拒绝服务(DoS)攻击,并开发了学习和检测DoS攻击的系统。该系统利用正常访问遵循TCP拥塞避免机制,并将测试反馈发送给怀疑未经授权访问的来源,以降低传输速率。通过检测源的响应,判断其是否是非法访问,并开发了在子网络入侵检测系统和相邻网络入侵检测系统之间共享检测到的非法访问信息所需的软件。该软件实现了对非法访问的广泛拦截,并结合检测系统构建了非法访问检测与消灭系统。我们在真实的网络上进行了实验。实验结果表明,该检测系统能够快速、准确地检测到攻击,实现了高检测率和低漏检率。
英文摘要
Recently, NIDS (Network-based Intrusion Detection System) has played an important role in Internet security system. However, the pattern matching technique used in NIDS is weak for new-type virus or unauthorized access, intentionally evasion act and is not expectable for next generation internet protocol IPv6 equipped with encryption. In this study, we propose a new access detection system which have learning function on subnetwork. Our goal is to develop next generation access detection system which include unknown illegal access detection structure, cooperate with NIDS and adapt to IPv6.In this research, we discussed about DoS (Denial of Service) attack that is difficult to detect in pattern matching technique and developed the system that learn and detect DoS attack This system exploit that the normal access follows the TCP congestion avoidance mechanism and will send test feedback to the source that being suspected of unauthorized access to decrease the transmission rate. By detecting the source's response, we can determine whether it is unauthorized access or not.Furthermore, we develop the software necessary for sharing information of detected unauthorized access among subnet NIDS and neighboring NIDS. This software makes it possible to block the unauthorized access extensively and we construct unauthorized access detection and extermination system combined with detection system. We had performed experiments over real network. As a result, we verified that detection-system is able to detect attack rapidly and accurately and we can realize high detection rate and low false negative rate.
期刊论文(16)
专著(0)
科研奖励(0)
会议论文
登录
查看更多内容
加藤寧: "ユーザトラヒックパターンの特徴付けによるUDP Flooding抑制方式"2004年電子情報通信学会総合大会講演論文集. B-7-14. 223 (2004)
Yasushi Kato:“基于用户流量模式特征的 UDP 洪泛抑制方法”2004 年 IEICE 大会记录 B-7-14 (2004)。
DOI:
--
发表时间:
期刊:
影响因子:
--
作者:
[]
通讯作者:
A Dummy Segment Based Bandwidth Probing Technique to Enhance the Performance of TCP over Heterogeneous Networks
基于虚拟段的带宽探测技术增强异构网络上的 TCP 性能
DOI:
--
发表时间:
2005
期刊:
IEEE Wireless Communications and Networking Conference
影响因子:
--
作者:
[A.SANO, K.NISHI, H.MIYANISHI, H.FUJIMOTO, Tarik Taleb]
通讯作者:
Tarik Taleb
A Recursive, Explicit and Fair Method to Efficiently and Fairly Adjust TCP Windows in Satellite Networks
卫星网络中高效公平调整 TCP 窗口的递归、显式、公平方法
DOI:
--
发表时间:
2004
期刊:
2004 IEEE International Conference on Communications 7
影响因子:
--
作者:
[Tarik Taleb, Tarik Taleb, Tarik Taleb, Tarik Taleb, Tarik Taleb, Tarik Taleb]
通讯作者:
Tarik Taleb
On-Demand Media Streaming to Hybrid Wired/Wireless Networks over Quasi-Geo Stationary Satellite Systems
通过准地球静止卫星系统将点播媒体流传输到混合有线/无线网络
DOI:
--
发表时间:
2005
期刊:
Elsevier Journal on Computer Networks Vol.47, No.2
影响因子:
--
作者:
[T.Taleb, N.Kato, Y.Nemoto]
通讯作者:
Y.Nemoto
和泉勇治: "異常検知のためのネットワーク特徴量抽出法に関する一考察"2004年電子情報通信学会総合大会講演論文集. SB-4-1. S-27 (2004)
Yuji Izumi:“异常检测的网络特征提取方法的研究”2004 年 IEICE 大会 S-27 会议记录(2004 年)。
DOI:
--
发表时间:
期刊:
影响因子:
--
作者:
[]
通讯作者:
共 7 条
Streaming Content Leakage Detection System for Encrypted Streams
-
批准号:22650010
-
项目类别:Grant-in-Aid for Challenging Exploratory Research
-
资助金额:$1.62万
-
财政年份:2010
-
负责人:KATO Nei
-
依托单位:
Research on Next Generation Multi-Layered Satellite Network Highly Compatible with Internet Protocol
-
批准号:20300021
-
项目类别:Grant-in-Aid for Scientific Research (B)
-
资助金额:$4.66万
-
财政年份:2008
-
负责人:KATO Nei
-
依托单位:
Research of next generation LEO satellite networks which have high affinity with the Internet
-
批准号:17500030
-
项目类别:Grant-in-Aid for Scientific Research (C)
-
资助金额:$2.31万
-
财政年份:2005
-
负责人:KATO Nei
-
依托单位:
A study of high sensitive illegal access detection system using distributed and cooperative scan detecting method.
-
批准号:13558038
-
项目类别:Grant-in-Aid for Scientific Research (B)
-
资助金额:$2.56万
-
财政年份:2001
-
负责人:KATO Nei
-
依托单位:
Construction of knowledge-based next generation document
-
批准号:11558043
-
项目类别:Grant-in-Aid for Scientific Research (B).
-
资助金额:$3.2万
-
财政年份:1999
-
负责人:KATO Nei
-
依托单位:
海外基金