| 講演抄録/キーワード |
| 講演名 |
2008-03-06 10:30
高パケットレートフローのオンライン検出手法 ○工藤隆則・滝根哲哉(阪大) IN2007-165 |
| 抄録 |
(和) |
DDoS攻撃などに起因する高パケットレートフローをスケーラビリティを確保しつつオンラインで検出する手法を提案する.本手法では,スケーラビリティを確保するためにパケットサンプリングを用いてトラヒックデータを取得する.また,オンラインでの検出を可能とするために,スライディングウインド方式を用いて解析対象データを更新する.このような方式では,高パケットレートフローを見逃す確率を十分小さく保ちながら,検出対象外の低レートフローを誤検出する確率が最小となるように,サンプリングレートやウィンドサイズ等の制御パラメタ値を決定する必要がある.そこで,この制御パラメタ決定問題を許容検出見逃し率や検出目標時間等を制約条件にもつ非線形計画問題として定式化し,最適制御パラメータの決定法を与えた.さらに,トレースデータに対して実験を行った結果,設計通り,良好に動作することを確認した. |
| (英) |
We present an online method which detects high packet-rate flows, such as DDoS attack flows, ensuring scalability. In our method, we collect traffic data by random packet-sampling to ensure scalability. At the same time, we use a sliding window technique in order to realize online detection when we renew sampled data which we have to examine. In this method, we have to determine the values of control parameters, such as the sampling rate and window size, to minimize the probability of the wrong detection, while keeping the probability of the detection error sufficiently low. We formulated the problem of determining control parameters as a nonlinear programming problem with constraints such as a permissible ratio of detection errors and permissible time for detection, and provide a way to determine the optimal control parameters. we then evaluate this method using measured traffic data and confirm that this method works well as designed. |
| キーワード |
(和) |
異常トラヒック検出 / パケットサンプリング / スライディングウインド方式 / 非線形計画問題 / / / / |
| (英) |
Anomaly Detection / Packet Sampling / Sliding Window Technique / Nonlinear Programming Problem / / / / |
| 文献情報 |
信学技報, vol. 107, no. 525, IN2007-165, pp. 37-42, 2008年3月. |
| 資料番号 |
IN2007-165 |
| 発行日 |
2008-02-28 (IN) |
| ISSN |
Print edition: ISSN 0913-5685 Online edition: ISSN 2432-6380 |
著作権に ついて |
技術研究報告に掲載された論文の著作権は電子情報通信学会に帰属します.(許諾番号:10GA0019/12GB0052/13GB0056/17GB0034/18GB0034) |
| PDFダウンロード |
IN2007-165 |