Traceback System of Malicious Accesses of the Internet based on Similarity of Communication Data
Traceback System of Malicious Accesses of the Internet based on Similarity of Communication Data
批准号:
18300017
负责人:
NEMOTO Yoshiaki
金额:
$4.43万
依托单位:
依托单位国家:
日本
项目类别:
Grant-in-Aid for Scientific Research (B)
财政年份:
2006
资助国家:
日本
项目状态:
已结题
起止时间:
2006 至 2007
中文摘要
基于网络流通信数据的相似性,开发了一种针对互联网恶意访问的溯源系统。为了保护通信隐私,提出了一种新的通信数据相似度评估建模方法。我们提出的建模方法用256维向量表示一个网络流,即一个TCP连接,该向量由8位码的出现概率组成。由于该建模方法实现了数据的不可逆转换,可以保护通信数据的隐私性。通过使用该建模,我们可以评估通信流的相似性。如果我们从网络蠕虫流中提取一个256维向量,我们可以通过评估向量与新观察到的流向量之间的相似性来检测同一种蠕虫流,因为同一种网络蠕虫的向量彼此非常相似。因此,我们开发了一种高精度的建模方法来识别具有相似内容的流。我们还开发了一个分布式蠕虫检测系统,该系统可以检测尚未生成检测签名的网络蠕虫。该检测系统具有全局检测器和局部检测器。如果局部检测器在短期内观察到多个类似的流,则局部检测器判断这种类似流的出现可能是由网络蠕虫活动引起的,并将类似流的平均256维向量发送给全局检测器。为了检测恶意访问的发生,全局检测器评估从本地检测器发送的向量之间的相似性。如果采用这种方式,我们提出的检测系统可以在不事先签名的情况下检测到恶意网络活动。基于向量的相似性,提出了一种新的追踪系统,可以发现新的恶意访问的释放点。为了找到恶意访问的释放点,回溯系统保留了三个要素:观察到恶意流量的检测时间、流量的src IP和流量的256维向量。追溯系统通过对这三个要素进行通信并对其相似性进行评估,从而找到恶意流的释放点。少
英文摘要
We developed a traceback system of malicious accesses of the Internet base on the similarity of communication data of network flows. In order to protect privacy of communication, we proposed a new modeling method to evaluate the similarity of communication data. Our proposed modeling method express a network flow, which is a TCP connection, with a 256-dimensional vector which consists of the occurrence probabilities of 8-bit codes. Since this modeling method id irreversible data translation, the privacy of communication data can ne protected. By using this modeling, we can evaluate the similarities of communication flows. If we have a 256-dimensioncal vector extracted from a network worm flow, we can detect the same kind of worm flow by evaluating the similarity between the vector and vector of newly observed flow because the vector of a same kind of network worm is very similar each other. Consequently, we developed a high accurate modeling method to identify flows which have similar … More contents.We also developed a distributed worm detection system which can detect network worms of which the detection signatures have not generated. The proposed detection system has Global Detector and Local Detectors. If multiple similar flows are observed at a Local Detector in a short term, the Local Detector judges that this emergence of similar flows can be occurred by network worm activities, and send the mean 256-dimensional vector of the similar flows to the Global Detector. In order to detect malicious accesses occurrence, Global Detector evaluate the similarity among the vectors sent from the Local Detectors. If the manner, our proposed detection system can detect malicious network activities without signatures made in advance.Based on the similarities of vectors, a new traceback system which can discover the point of release of a new malicious access have been proposed. To find the point of release of a malicious access, the traceback system keeps three elements: detection time when a malicious flow was observed, src IP of the flow and the 256-dimensional vector of the flow. By communicating the three elements and evaluating the similarity, the traceback system can find the point of release of the malicious flow. Less
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
登录
查看更多内容
An Efficient Signature-Based Approach for Automatic Detection of Internet Worms over Large-Scale Networks
一种有效的基于签名的方法,用于自动检测大规模网络上的网络蠕虫
DOI:
--
发表时间:
2006
期刊:
Proc. of IEEE Int. Conf. Commun. (CDROM)
影响因子:
--
作者:
[K.Simkhada, T.Taleb, Y.Waizumi, A.Jamalipour, N.Kato, Y.Nemoto]
通讯作者:
Y.Nemoto
An Evaluation of Transition Pattern of Payload Legnth for Network Application Identification
网络应用识别有效负载长度转换模式的评估
DOI:
--
发表时间:
2007
期刊:
影响因子:
--
作者:
[S. Yagi, Y. Waizumi, H. Tsunoda, Y. Nemoto]
通讯作者:
Y. Nemoto
帯域利用状態に着目したパルス型DoS検知の誤検知と観測コストの低減
减少脉冲 DoS 检测中的误报和观察成本,重点关注带宽使用状态
DOI:
--
发表时间:
2006
期刊:
影响因子:
--
作者:
[荒井健二郎, 角田裕, 和泉勇治, 根元義章]
通讯作者:
根元義章
Network Application Identification using Transition Pattern of Packets
使用数据包转换模式进行网络应用识别
DOI:
--
发表时间:
2006
期刊:
影响因子:
--
作者:
[Y. Waizumi, Y. Nemoto]
通讯作者:
Y. Nemoto
相関関係ヒストグラムによるネットワーク状態評価方式
基于相关直方图的网络状态评估方法
DOI:
--
发表时间:
2006
期刊:
影响因子:
--
作者:
[和泉勇治, 廣瀬 淳一, 角田 裕 根元義章]
通讯作者:
角田 裕 根元義章
共 57 条
Distributed Network anomaly Detection using Multiresolutional Observables
-
批准号:20300023
-
项目类别:Grant-in-Aid for Scientific Research (B)
-
资助金额:$5.74万
-
财政年份:2008
-
负责人:NEMOTO Yoshiaki
-
依托单位:
Next Generation Automatic Trace Back System for Broad Unlawful Access Based on Time-Series Analysis of Trafic Patterns
-
批准号:14380172
-
项目类别:Grant-in-Aid for Scientific Research (B)
-
资助金额:$4.03万
-
财政年份:2002
-
负责人:NEMOTO Yoshiaki
-
依托单位:
Organization-defense Style Security System by using Detection of Omens of Illegal Access.
-
批准号:12558036
-
项目类别:Grant-in-Aid for Scientific Research (B)
-
资助金额:$4.16万
-
财政年份:2000
-
负责人:NEMOTO Yoshiaki
-
依托单位:
Solution of the electromagnetic noise produced from small electric appliance by real-time parallel measurements
-
批准号:11834003
-
项目类别:Grant-in-Aid for Scientific Research (C)
-
资助金额:$2.24万
-
财政年份:1999
-
负责人:NEMOTO Yoshiaki
-
依托单位:
A study of Real-time fault detecting system using information filtering technique
-
批准号:09680388
-
项目类别:Grant-in-Aid for Scientific Research (C)
-
资助金额:$1.73万
-
财政年份:1997
-
负责人:NEMOTO Yoshiaki
-
依托单位:
Construction of Distributed Network Management System for High speed and Large Scale Information Network
-
批准号:08558033
-
项目类别:Grant-in-Aid for Scientific Research (B)
-
资助金额:$4.1万
-
财政年份:1996
-
负责人:NEMOTO Yoshiaki
-
依托单位: