講演名 2012/3/8
Euclidian- and Cosine-Distances based Detection of Distributed Host Search Attacks
,
PDFダウンロードページ PDFダウンロードページへ
抄録(和)
抄録(英) We statistically investigated the total PTR resource record (RR) based DNS query request packet traffic from the Internet to the top domain DNS server in a university campus network through January 1st to December 31st, 2011. The obtained results are: (1) We found twelve host search (HS) attacks in the scores for detection method using the calculated Euclidean distances between the observed IP address and the last observed IP address in the DNS query keywords by employing both threshold ranges of 1.0-2.0 (consecutive) and 150.2-210.4 (random). However, we found nineteen HS attacks in the scores using the calculated cosine distance between the DNS query IP addresses (threshold ranges of 0.75-0.83 and 0.9-1.0). (3) In the newly found HS attacks, we observed that the source IP addresses of the HS attack DNS query packets are distributed Therefore, it can be concluded that the cosine distance based detection technology can detect the source IP address-distributed host search attack.
キーワード(和)
キーワード(英)
資料番号 Vol.2012-IOT-16 No.31
発行日

研究会情報
研究会 IA
開催期間 2012/3/8(から1日開催)
開催地(和)
開催地(英)
テーマ(和)
テーマ(英)
委員長氏名(和)
委員長氏名(英)
副委員長氏名(和)
副委員長氏名(英)
幹事氏名(和)
幹事氏名(英)
幹事補佐氏名(和)
幹事補佐氏名(英)

講演論文情報詳細
申込み研究会 Internet Architecture(IA)
本文の言語 ENG
タイトル(和)
サブタイトル(和)
タイトル(英) Euclidian- and Cosine-Distances based Detection of Distributed Host Search Attacks
サブタイトル(和)
キーワード(1)(和/英)
第 1 著者 氏名(和/英) / Yasuo Musashi
第 1 著者 所属(和/英)
Center for Multimedia and Information Technologies (CMIT), Kumamoto University
発表年月日 2012/3/8
資料番号 Vol.2012-IOT-16 No.31
巻番号(vol) vol.111
号番号(no) 485
ページ範囲 pp.-
ページ数 6
発行日