Paper Abstract and Keywords |
Presentation |
2007-03-08 11:10
Effect of sampling rate and monitoring granularity on anomaly detectability Keisuke Ishibashi, Ryoichi Kawahara, Tatsuya Mori, Tsuyoshi Kondoh (NTT), Shoichiro Asano (NII) IN2006-201 |
Abstract |
(in Japanese) |
(See Japanese page) |
(in English) |
In this paper, we quantitatively evaluate how sampling decrease detectability of anomalous traffic. We build equations to calculate False Positive Ratio (FPR) and False Negative Ratio (FNR) with given sampling rate, statistics of normal traffic and volume of anomaly to be detected. We then show by changing measurement granularity, we can detect anomalies even with low sampling rate by using the relationship between the mean and variance of aggregated flows. With those equations, we can provide answers to the questions that arise in actual network operators, and had not been answered yet, such as which sampling rate to set in order to find the given volume of anomaly, or, if the sampling is too high for the actual operation, then which granularity is optimal to find the anomaly with given lower limit of sampling rate. |
Keyword |
(in Japanese) |
(See Japanese page) |
(in English) |
DDoS / anomay detection / sampling / / / / / |
Reference Info. |
IEICE Tech. Rep., vol. 106, no. 578, IN2006-201, pp. 125-130, March 2007. |
Paper # |
IN2006-201 |
Date of Issue |
2007-03-01 (IN) |
ISSN |
Print edition: ISSN 0913-5685 Online edition: ISSN 2432-6380 |
Copyright and reproduction |
All rights are reserved and no part of this publication may be reproduced or transmitted in any form or by any means, electronic or mechanical, including photocopy, recording, or any information storage and retrieval system, without permission in writing from the publisher. Notwithstanding, instructors are permitted to photocopy isolated articles for noncommercial classroom use without fee. (License No.: 10GA0019/12GB0052/13GB0056/17GB0034/18GB0034) |
Download PDF |
IN2006-201 |
Conference Information |
Committee |
NS IN |
Conference Date |
2007-03-08 - 2007-03-09 |
Place (in Japanese) |
(See Japanese page) |
Place (in English) |
Okinawa Convention Center |
Topics (in Japanese) |
(See Japanese page) |
Topics (in English) |
|
Paper Information |
Registration To |
IN |
Conference Code |
2007-03-NS-IN |
Language |
Japanese |
Title (in Japanese) |
(See Japanese page) |
Sub Title (in Japanese) |
(See Japanese page) |
Title (in English) |
Effect of sampling rate and monitoring granularity on anomaly detectability |
Sub Title (in English) |
|
Keyword(1) |
DDoS |
Keyword(2) |
anomay detection |
Keyword(3) |
sampling |
Keyword(4) |
|
Keyword(5) |
|
Keyword(6) |
|
Keyword(7) |
|
Keyword(8) |
|
1st Author's Name |
Keisuke Ishibashi |
1st Author's Affiliation |
NTT (NTT) |
2nd Author's Name |
Ryoichi Kawahara |
2nd Author's Affiliation |
NTT (NTT) |
3rd Author's Name |
Tatsuya Mori |
3rd Author's Affiliation |
NTT (NTT) |
4th Author's Name |
Tsuyoshi Kondoh |
4th Author's Affiliation |
NTT (NTT) |
5th Author's Name |
Shoichiro Asano |
5th Author's Affiliation |
National Institute of Informatics (NII) |
6th Author's Name |
|
6th Author's Affiliation |
() |
7th Author's Name |
|
7th Author's Affiliation |
() |
8th Author's Name |
|
8th Author's Affiliation |
() |
9th Author's Name |
|
9th Author's Affiliation |
() |
10th Author's Name |
|
10th Author's Affiliation |
() |
11th Author's Name |
|
11th Author's Affiliation |
() |
12th Author's Name |
|
12th Author's Affiliation |
() |
13th Author's Name |
|
13th Author's Affiliation |
() |
14th Author's Name |
|
14th Author's Affiliation |
() |
15th Author's Name |
|
15th Author's Affiliation |
() |
16th Author's Name |
|
16th Author's Affiliation |
() |
17th Author's Name |
|
17th Author's Affiliation |
() |
18th Author's Name |
|
18th Author's Affiliation |
() |
19th Author's Name |
|
19th Author's Affiliation |
() |
20th Author's Name |
|
20th Author's Affiliation |
() |
Speaker |
Author-1 |
Date Time |
2007-03-08 11:10:00 |
Presentation Time |
20 minutes |
Registration for |
IN |
Paper # |
IN2006-201 |
Volume (vol) |
vol.106 |
Number (no) |
no.578 |
Page |
pp.125-130 |
#Pages |
6 |
Date of Issue |
2007-03-01 (IN) |
|