Presentation 2008-05-16
A method to reduce false positive of Anomaly Detection System
Yuka Ikebe, Takehiro Nakayama, Masaji Katagiri, Satoshi Kawasaki, Hirotake Abe, Takahiro Shinagawa, Kazuhiko Kato,
PDF Download Page PDF download Page Link
Abstract(in Japanese) (See Japanese page)
Abstract(in English) We proposed a new anomaly detection system. In this system, software behavior that deviates from a model representing normal behavior is considered to be anomaly. Generally speaking, it is impossible to cover software behavior exhaustively by the model, which could cause increase of false positive event. To resolve this problem, we proposed a method to assess the anomalousness of behavior not covered by the model. From the experimental results, it is clarified that the proposed method can reduce false positive.
Keyword(in Japanese) (See Japanese page)
Keyword(in English) Anomaly Detection System / Anti virus technology
Paper # ISEC2008-8
Date of Issue

Conference Information
Committee ISEC
Conference Date 2008/5/9(1days)
Place (in Japanese) (See Japanese page)
Place (in English)
Topics (in Japanese) (See Japanese page)
Topics (in English)
Chair
Vice Chair
Secretary
Assistant

Paper Information
Registration To Information Security (ISEC)
Language JPN
Title (in Japanese) (See Japanese page)
Sub Title (in Japanese) (See Japanese page)
Title (in English) A method to reduce false positive of Anomaly Detection System
Sub Title (in English)
Keyword(1) Anomaly Detection System
Keyword(2) Anti virus technology
1st Author's Name Yuka Ikebe
1st Author's Affiliation NTTDoCoMo Inc.()
2nd Author's Name Takehiro Nakayama
2nd Author's Affiliation NTTDoCoMo Inc.
3rd Author's Name Masaji Katagiri
3rd Author's Affiliation NTTDoCoMo Inc.
4th Author's Name Satoshi Kawasaki
4th Author's Affiliation University of Tsukuba
5th Author's Name Hirotake Abe
5th Author's Affiliation Toyohashi University of Technology
6th Author's Name Takahiro Shinagawa
6th Author's Affiliation University of Tsukuba
7th Author's Name Kazuhiko Kato
7th Author's Affiliation University of Tsukuba
Date 2008-05-16
Paper # ISEC2008-8
Volume (vol) vol.108
Number (no) 38
Page pp.pp.-
#Pages 7
Date of Issue