• Search Research Projects
  • Search Researchers
  • How to Use
  1. Back to previous page

Construction of A Network Security System based on Active Collection of Illegal Access Information

Research Project

Project/Area Number 16300010
Research Category

Grant-in-Aid for Scientific Research (B)

Allocation TypeSingle-year Grants
Section一般
Research Field Computer system/Network
Research InstitutionTohoku University

Principal Investigator

NEMOTO Yoshiaki  Tohoku University, Graduate School of Information Sciences, Professor, 大学院・情報科学研究科, 教授 (60005527)

Co-Investigator(Kenkyū-buntansha) KATO Nei  Tohoku University, Graduate School of Information Sciences, Professor, 大学院・情報科学研究科, 教授 (00236168)
WAIZUMI Yuji  Tohoku University, Graduate School of Information Sciences, Lecturer, 大学院・情報科学研究科, 講師 (90333872)
Project Period (FY) 2004 – 2005
Project Status Completed (Fiscal Year 2005)
Budget Amount *help
¥6,000,000 (Direct Cost: ¥6,000,000)
Fiscal Year 2005: ¥2,200,000 (Direct Cost: ¥2,200,000)
Fiscal Year 2004: ¥3,800,000 (Direct Cost: ¥3,800,000)
KeywordsDistributed Misuse Detection / Communicated Contents Similarity / Automatic Signature Generation / Common Token / Histogram / Clustering / 不正アクセス / 異常検知 / 状態記述方式 / 状態判別 / おとりシステム / ネットワークセキュリティ
Research Abstract

It is important to early detect a novel illegal access for network security. In order to early detect the access, we developed some anomaly detection techniques which can detect unknown attacks, an early detection technique based on contents similarity of communication and an extracting method of characteristic information of illegal accesses.
On the anomaly detection, we proposed three anomaly detection methods based on our analysis of state change of network traffic when illegal accesses occurred, and achieve the world's highest level of detection accuracy using benchmark database. We also developed a distributed early detection system of diffusion of computer viruses. The detection system uses the traffic occurred which the computer viruses copy themselves to many hosts on the Internet when they diffuse. The system adopts a similarity evaluation method for communication contents using histogram of codes of packet payloads. We confirmed that the system possesses extremely high detection accuracy with very low false positives.
Moreover, we developed an automatic signature generation method using virus samples that were detected by the above system from common tokens of the detected viruses. And we discovered that the common tokes can be used to detect subspecies of viruses which can be detected already created signatures.

Report

(3 results)
  • 2005 Annual Research Report   Final Research Report Summary
  • 2004 Annual Research Report
  • Research Products

    (19 results)

All 2006 2005 2004

All Journal Article (19 results)

  • [Journal Article] A Simple Response Packet Confirmation Method for DRDoS Detection2006

    • Author(s)
      H.TSUNODA, K.OHTA, A.YAMAMOTO, Y.NEMOTO
    • Journal Title

      Proc. of 8th International Conference on Advanced Communication Technology 1(CDROM)

    • Description
      「研究成果報告書概要(和文)」より
    • Related Report
      2005 Final Research Report Summary
  • [Journal Article] A Simple Response Packet Confirmation Method for DRDoS Detection2006

    • Author(s)
      H.TSUNODA, K.OHTA, A.YAMAMOTO, Y.NEMOTO
    • Journal Title

      Proc.of 8th International Conference on Advanced Communication Technology (CDROM)

    • Description
      「研究成果報告書概要(欧文)」より
    • Related Report
      2005 Final Research Report Summary
  • [Journal Article] A Simple Response Packet Confirmation Method for DRDoS Detection2006

    • Author(s)
      H.TSUNODA, K.OHTA, A.YAMAMOTO, Y.NEMOTO
    • Journal Title

      Proc.of 8th International Conference on Advanced Communication Technology 1(CDROM)

    • Related Report
      2005 Annual Research Report
  • [Journal Article] On-Demand Media Streaming to Hybrid Wired/Wireless Networks over Quasi-Geo Stationary Satellite Systems2005

    • Author(s)
      T.Taleb, N.Kato, Y.Nemoto
    • Journal Title

      Elsevier Journal on Computer Networks Vol.47, No.2

      Pages: 287-306

    • Description
      「研究成果報告書概要(和文)」より
    • Related Report
      2005 Final Research Report Summary 2004 Annual Research Report
  • [Journal Article] Recent Trends in IP/NGEO Satellite Communication Systems : Transport, Routing, and Mobility Management2005

    • Author(s)
      T.Taleb, N.Kato, Y.Nemoto
    • Journal Title

      IEEE Wireless Communications Magazine 12・5

      Pages: 63-69

    • Description
      「研究成果報告書概要(和文)」より
    • Related Report
      2005 Annual Research Report 2005 Final Research Report Summary
  • [Journal Article] A New Network Anomaly Detection Technique Based on Per-flow and Per-service Statistics2005

    • Author(s)
      Y.Waizumi, D.Kudo, N.Kato, Y.Nemoto
    • Journal Title

      in Proc. of Int. Conf. on Computional Intelligence and Security 1

      Pages: 252-259

    • Description
      「研究成果報告書概要(和文)」より
    • Related Report
      2005 Final Research Report Summary
  • [Journal Article] Differencing Worm Flows and Normal Flows for Automatic Generation of Worm Signatures2005

    • Author(s)
      K.Simkhada, H.Tsunoda, Y.Waizumi, Y.Nemoto
    • Journal Title

      The First IEEE International Workshop on Security and Pervasive Multimedia Environments 2

      Pages: 680-685

    • Description
      「研究成果報告書概要(和文)」より
    • Related Report
      2005 Annual Research Report 2005 Final Research Report Summary
  • [Journal Article] Securing Hybrid Wired/Mobile IP Networks from TCP-Flooding Based Denial-of-Service Attacks2005

    • Author(s)
      T.Taleb, H.Nishiyama, N.Kato, Y.Nemoto
    • Journal Title

      in Proc. of IEEE Globecom 1(CDROM)

    • Description
      「研究成果報告書概要(和文)」より
    • Related Report
      2005 Final Research Report Summary
  • [Journal Article] A Dynamic and Efficient MAP Selection for Mobile IPv6 Networks2005

    • Author(s)
      T.Taleb, T.Suzuki, N.Kato, Y.Nemoto
    • Journal Title

      in Proc. of IEEE Globecom 1(CDROM)

    • Description
      「研究成果報告書概要(和文)」より
    • Related Report
      2005 Final Research Report Summary
  • [Journal Article] Recent Trends in IP/NGEO Satellite Communication Systems : Transport, Routing, and Mobility Management2005

    • Author(s)
      T.Taleb, N.Kato, Y.Nemoto
    • Journal Title

      IEEE Wireless Communications Magazine Dec.5

      Pages: 63-69

    • Description
      「研究成果報告書概要(欧文)」より
    • Related Report
      2005 Final Research Report Summary
  • [Journal Article] A New Network Anomaly Detection Technique Based on Per-flow and Per-service Statistics2005

    • Author(s)
      Y.Waizumi, D.Kudo, N.Kato, Y.Nemoto
    • Journal Title

      Proc.of Int.Conf.on Computional Intelligence and Security 1

      Pages: 252-259

    • Description
      「研究成果報告書概要(欧文)」より
    • Related Report
      2005 Annual Research Report 2005 Final Research Report Summary
  • [Journal Article] Securing Hybrid Wired/Mobile IP Networks from TCP-Flooding Based Denial-of-Service Attacks2005

    • Author(s)
      T.Taleb, H.Nishiyama, N.Kato, Y.Nemoto
    • Journal Title

      Proc.of IEEE Globecom 1(CDROM)

    • Description
      「研究成果報告書概要(欧文)」より
    • Related Report
      2005 Annual Research Report 2005 Final Research Report Summary
  • [Journal Article] A Dynamic and Efficient MAP Selection for Mobile IPv6 Networks2005

    • Author(s)
      T.Taleb, T.Suzuki, N.Kato, Y.Nemoto
    • Journal Title

      Proc.of IEEE Globecom 1(CDROM)

    • Description
      「研究成果報告書概要(欧文)」より
    • Related Report
      2005 Annual Research Report 2005 Final Research Report Summary
  • [Journal Article] On-Demand Media Streaming to Hybrid Wired/Wireless Networks over Quasi-Geo Stationary Satellite Systems2005

    • Author(s)
      T.Taleb, N.Kato, Y.Nemoto
    • Journal Title

      Elsevier Journal on computer Networks Vol.47,No.2

      Pages: 287-306

    • Related Report
      2005 Annual Research Report
  • [Journal Article] Detecting and Tracing DDoS Attacks in the Traffic Analysis Using Auto Regressive Model2004

    • Author(s)
      Y.UCHIYAMA, Y.WAIZUMI, N.KATO, Y.NEMOTO
    • Journal Title

      IEICE TRANSACTIONS on Information and Systems Vol.E87-D, No.12

      Pages: 2635-2643

    • NAID

      110003213873

    • Related Report
      2004 Annual Research Report
  • [Journal Article] 適応型帯域推定とSACKを組み合わせた無線ネットワーク向けTCP2004

    • Author(s)
      佐々木 貴之, 角田 裕, 太田 耕平, 加藤 寧, 根本 義章
    • Journal Title

      電子情報通信学会論文誌B Vol.J87-B No.10

      Pages: 1657-1667

    • NAID

      110003170640

    • Related Report
      2004 Annual Research Report
  • [Journal Article] A Satellite Selection Method for Walker Delta LEO Satellite Networks2004

    • Author(s)
      U.Dharmaratna, H.Tsunoda, N.Kato, Y.Nemoto
    • Journal Title

      IEICE Trans.Commun Vol.E87-B, No.8

      Pages: 2124-2131

    • NAID

      110003222474

    • Related Report
      2004 Annual Research Report
  • [Journal Article] A Polynomial Factorization Approach for the Discrete Time GIX/G/1/K Queue2004

    • Author(s)
      Pinai LINWONG, Nei KATO, Yoshiaki NEMOTO
    • Journal Title

      Methodology and Computing in Applied Probability 6

      Pages: 277-291

    • Related Report
      2004 Annual Research Report
  • [Journal Article] An Explicit and Fair Adjustment Method to Enhance TCP Effieciency and Fairness over Multi-Hops Satellite Networks2004

    • Author(s)
      Tarik TALEB, Nei KATO, Yoshiaki NEMOTO
    • Journal Title

      IEEE Journal on Selected Areas in Communications Vol.22, No.2

      Pages: 371-387

    • Related Report
      2004 Annual Research Report

URL: 

Published: 2004-04-01   Modified: 2016-04-21  

Information User Guide FAQ News Terms of Use Attribution of KAKENHI

Powered by NII kakenhi