Paper Abstract and Keywords |
Presentation |
2011-03-11 17:30
Identifying the Anomalous Traffic Using unsupervised learning of Traffic Distribution Hiroshi Yoshida, Haruo Oishi, Akiyuki Takeda, Hideaki Harada (NTT) ICM2010-75 |
Abstract |
(in Japanese) |
(See Japanese page) |
(in English) |
DDoS (Distributed Denial of Service) attacks cause serious damage for services. For a early recovery against attacks, quick detection of attacks is important. However, network providers are not allowed to investigate network traffics of their customers directly due to the privacy of communications so that analysis of protocol headers to find malicious packets is not applicable for detection. This paper presents an algorithm to judge normal and aberrant (under DDoS attacks) statuses of network from continuous traffic rate measurement. The algorism finds the threshold of normal and aberrant statuses repeatedly with the probabilistically highest accuracy utilizing the characteristic of the traffic rate distribution. |
Keyword |
(in Japanese) |
(See Japanese page) |
(in English) |
DDoS attacks, / traffic monitoring, / normal distribution / machine learning / / / / |
Reference Info. |
IEICE Tech. Rep., vol. 110, no. 466, ICM2010-75, pp. 121-126, March 2011. |
Paper # |
ICM2010-75 |
Date of Issue |
2011-03-03 (ICM) |
ISSN |
Print edition: ISSN 0913-5685 Online edition: ISSN 2432-6380 |
Copyright and reproduction |
All rights are reserved and no part of this publication may be reproduced or transmitted in any form or by any means, electronic or mechanical, including photocopy, recording, or any information storage and retrieval system, without permission in writing from the publisher. Notwithstanding, instructors are permitted to photocopy isolated articles for noncommercial classroom use without fee. (License No.: 10GA0019/12GB0052/13GB0056/17GB0034/18GB0034) |
Download PDF |
ICM2010-75 |
Conference Information |
Committee |
ICM |
Conference Date |
2011-03-10 - 2011-03-11 |
Place (in Japanese) |
(See Japanese page) |
Place (in English) |
Miyakojima Marine Terminal |
Topics (in Japanese) |
(See Japanese page) |
Topics (in English) |
Element Management, Management Functionalities, Operations and Management Technologies |
Paper Information |
Registration To |
ICM |
Conference Code |
2011-03-ICM |
Language |
Japanese |
Title (in Japanese) |
(See Japanese page) |
Sub Title (in Japanese) |
(See Japanese page) |
Title (in English) |
Identifying the Anomalous Traffic Using unsupervised learning of Traffic Distribution |
Sub Title (in English) |
|
Keyword(1) |
DDoS attacks, |
Keyword(2) |
traffic monitoring, |
Keyword(3) |
normal distribution |
Keyword(4) |
machine learning |
Keyword(5) |
|
Keyword(6) |
|
Keyword(7) |
|
Keyword(8) |
|
1st Author's Name |
Hiroshi Yoshida |
1st Author's Affiliation |
NTT (NTT) |
2nd Author's Name |
Haruo Oishi |
2nd Author's Affiliation |
NTT (NTT) |
3rd Author's Name |
Akiyuki Takeda |
3rd Author's Affiliation |
NTT (NTT) |
4th Author's Name |
Hideaki Harada |
4th Author's Affiliation |
NTT (NTT) |
5th Author's Name |
|
5th Author's Affiliation |
() |
6th Author's Name |
|
6th Author's Affiliation |
() |
7th Author's Name |
|
7th Author's Affiliation |
() |
8th Author's Name |
|
8th Author's Affiliation |
() |
9th Author's Name |
|
9th Author's Affiliation |
() |
10th Author's Name |
|
10th Author's Affiliation |
() |
11th Author's Name |
|
11th Author's Affiliation |
() |
12th Author's Name |
|
12th Author's Affiliation |
() |
13th Author's Name |
|
13th Author's Affiliation |
() |
14th Author's Name |
|
14th Author's Affiliation |
() |
15th Author's Name |
|
15th Author's Affiliation |
() |
16th Author's Name |
|
16th Author's Affiliation |
() |
17th Author's Name |
|
17th Author's Affiliation |
() |
18th Author's Name |
|
18th Author's Affiliation |
() |
19th Author's Name |
|
19th Author's Affiliation |
() |
20th Author's Name |
|
20th Author's Affiliation |
() |
Speaker |
Author-1 |
Date Time |
2011-03-11 17:30:00 |
Presentation Time |
20 minutes |
Registration for |
ICM |
Paper # |
ICM2010-75 |
Volume (vol) |
vol.110 |
Number (no) |
no.466 |
Page |
pp.121-126 |
#Pages |
6 |
Date of Issue |
2011-03-03 (ICM) |
|