Paper Abstract and Keywords |
Presentation |
2007-09-21 09:30
A method of detecting network anomalies for periodic traffic Shigeaki Harada, Ryoichi Kawahara, Tatsuya Mori, Noriaki Kamiyama, Hideaki Yoshino (NTT) IN2007-59 |
Abstract |
(in Japanese) |
(See Japanese page) |
(in English) |
We present a method of detecting network anomalies, such as DDoS attacks and flash crowds, automatically in real time.
We evaluated this method using measured traffic data and found that it successfully differentiates suspicious traffic.
In this paper, we focus on periodic traffic which have daily cycle and/or weekly cycle,
and we show that the accuracy of differentiation is improved using such periodic tendency in anomaly detection.
Our method differentiates suspicious traffic that have different statistical characteristics from normal traffic.
At the same time, our method learns periodic large-volume traffic, such as operating traffic, and considers them as legitimate at the end.
Therefore, our method has fewer false-positives than original methods which do not consider periodic tendency. |
Keyword |
(in Japanese) |
(See Japanese page) |
(in English) |
DDoS attack / Anomaly Detection / Periodic traffic / Kalman Filter / Hoeffding-Azuma inequalit / / / |
Reference Info. |
IEICE Tech. Rep., vol. 107, no. 222, IN2007-59, pp. 93-98, Sept. 2007. |
Paper # |
IN2007-59 |
Date of Issue |
2007-09-13 (IN) |
ISSN |
Print edition: ISSN 0913-5685 Online edition: ISSN 2432-6380 |
Copyright and reproduction |
All rights are reserved and no part of this publication may be reproduced or transmitted in any form or by any means, electronic or mechanical, including photocopy, recording, or any information storage and retrieval system, without permission in writing from the publisher. Notwithstanding, instructors are permitted to photocopy isolated articles for noncommercial classroom use without fee. (License No.: 10GA0019/12GB0052/13GB0056/17GB0034/18GB0034) |
Download PDF |
IN2007-59 |
Conference Information |
Committee |
NS CS IN |
Conference Date |
2007-09-20 - 2007-09-21 |
Place (in Japanese) |
(See Japanese page) |
Place (in English) |
Tohoku University |
Topics (in Japanese) |
(See Japanese page) |
Topics (in English) |
Overlay networks, VPN, DDos, network security, p2p communications, network software, etc. |
Paper Information |
Registration To |
IN |
Conference Code |
2007-09-NS-CS-IN |
Language |
Japanese |
Title (in Japanese) |
(See Japanese page) |
Sub Title (in Japanese) |
(See Japanese page) |
Title (in English) |
A method of detecting network anomalies for periodic traffic |
Sub Title (in English) |
|
Keyword(1) |
DDoS attack |
Keyword(2) |
Anomaly Detection |
Keyword(3) |
Periodic traffic |
Keyword(4) |
Kalman Filter |
Keyword(5) |
Hoeffding-Azuma inequalit |
Keyword(6) |
|
Keyword(7) |
|
Keyword(8) |
|
1st Author's Name |
Shigeaki Harada |
1st Author's Affiliation |
NTT Corporation (NTT) |
2nd Author's Name |
Ryoichi Kawahara |
2nd Author's Affiliation |
NTT Corporation (NTT) |
3rd Author's Name |
Tatsuya Mori |
3rd Author's Affiliation |
NTT Corporation (NTT) |
4th Author's Name |
Noriaki Kamiyama |
4th Author's Affiliation |
NTT Corporation (NTT) |
5th Author's Name |
Hideaki Yoshino |
5th Author's Affiliation |
NTT Corporation (NTT) |
6th Author's Name |
|
6th Author's Affiliation |
() |
7th Author's Name |
|
7th Author's Affiliation |
() |
8th Author's Name |
|
8th Author's Affiliation |
() |
9th Author's Name |
|
9th Author's Affiliation |
() |
10th Author's Name |
|
10th Author's Affiliation |
() |
11th Author's Name |
|
11th Author's Affiliation |
() |
12th Author's Name |
|
12th Author's Affiliation |
() |
13th Author's Name |
|
13th Author's Affiliation |
() |
14th Author's Name |
|
14th Author's Affiliation |
() |
15th Author's Name |
|
15th Author's Affiliation |
() |
16th Author's Name |
|
16th Author's Affiliation |
() |
17th Author's Name |
|
17th Author's Affiliation |
() |
18th Author's Name |
|
18th Author's Affiliation |
() |
19th Author's Name |
|
19th Author's Affiliation |
() |
20th Author's Name |
|
20th Author's Affiliation |
() |
Speaker |
Author-1 |
Date Time |
2007-09-21 09:30:00 |
Presentation Time |
20 minutes |
Registration for |
IN |
Paper # |
IN2007-59 |
Volume (vol) |
vol.107 |
Number (no) |
no.222 |
Page |
pp.93-98 |
#Pages |
6 |
Date of Issue |
2007-09-13 (IN) |
|