Presentation 2021-03-01
Method of Similarity Evaluation among Incidents for Multi-Located Network
Masahito Kumazaki, Hirokazu Hasegawa, Yukiko Yamaguchi, Hajime Shimada, Hiroki Takakura,
PDF Download Page PDF download Page Link
Abstract(in Japanese) (See Japanese page)
Abstract(in English) In an organization computer network which consists of multiple sites, there are differences in security strength between the headquarter and other sites. It makes it difficult in protecting their networks from targeted attacks because weak sites are used for the initial intrusion. Early detection and response against the attacks are important to mitigate damages, however, it is difficult to conduct them in the current general management style of networks. To solve this problem, we already proposed an incident response support system for multiple located networks. This system searches incidents similar to underway one and reports its correspondence status to administrators. In this paper, we discussed a similarity calculation method between incidents and evaluated it.
Keyword(in Japanese) (See Japanese page)
Keyword(in English) Targeted Attacks / Security Incident Response / Similarity Detection
Paper # ICSS2020-31
Date of Issue 2021-02-22 (ICSS)

Conference Information
Committee ICSS / IPSJ-SPT
Conference Date 2021/3/1(2days)
Place (in Japanese) (See Japanese page)
Place (in English) Online
Topics (in Japanese) (See Japanese page)
Topics (in English) Security, Trust, etc.
Chair Hiroki Takakura(NII)
Vice Chair Katsunari Yoshioka(Yokohama National Univ.) / Kazunori Kamiya(NTT)
Secretary Katsunari Yoshioka(NICT) / Kazunori Kamiya(KDDI labs.)
Assistant Keisuke Kito(Mitsubishi Electric) / Toshihiro Yamauchi(Okayama Univ.)

Paper Information
Registration To Technical Committee on Information and Communication System Security / Special Interest Group on Security Psychology and Trust
Language JPN
Title (in Japanese) (See Japanese page)
Sub Title (in Japanese) (See Japanese page)
Title (in English) Method of Similarity Evaluation among Incidents for Multi-Located Network
Sub Title (in English)
Keyword(1) Targeted Attacks
Keyword(2) Security Incident Response
Keyword(3) Similarity Detection
1st Author's Name Masahito Kumazaki
1st Author's Affiliation Nagoya University(Nagoya Univ.)
2nd Author's Name Hirokazu Hasegawa
2nd Author's Affiliation Nagoya University(Nagoya Univ.)
3rd Author's Name Yukiko Yamaguchi
3rd Author's Affiliation Nagoya University(Nagoya Univ.)
4th Author's Name Hajime Shimada
4th Author's Affiliation Nagoya University(Nagoya Univ.)
5th Author's Name Hiroki Takakura
5th Author's Affiliation National Institute of Informatics(NII)
Date 2021-03-01
Paper # ICSS2020-31
Volume (vol) vol.120
Number (no) ICSS-384
Page pp.pp.31-36(ICSS),
#Pages 6
Date of Issue 2021-02-22 (ICSS)