Distributed Network anomaly Detection using Multiresolutional Observables
Project/Area Number |
20300023
|
Research Category |
Grant-in-Aid for Scientific Research (B)
|
Allocation Type | Single-year Grants |
Section | 一般 |
Research Field |
Computer system/Network
|
Research Institution | Tohoku University |
Principal Investigator |
NEMOTO Yoshiaki 東北大学, 大学院・情報科学研究科, 理事 (60005527)
|
Co-Investigator(Kenkyū-buntansha) |
WAIZUMI Yuji 東北大学, 大学院・情報科学研究科, 准教授 (90333872)
TSUNODA Hiroshi 東北工業大学, 工学部・情報通信工学科, 講師 (30400302)
|
Project Period (FY) |
2008 – 2010
|
Project Status |
Completed (Fiscal Year 2010)
|
Budget Amount *help |
¥8,970,000 (Direct Cost: ¥6,900,000、Indirect Cost: ¥2,070,000)
Fiscal Year 2010: ¥2,600,000 (Direct Cost: ¥2,000,000、Indirect Cost: ¥600,000)
Fiscal Year 2009: ¥1,820,000 (Direct Cost: ¥1,400,000、Indirect Cost: ¥420,000)
Fiscal Year 2008: ¥4,550,000 (Direct Cost: ¥3,500,000、Indirect Cost: ¥1,050,000)
|
Keywords | 情報システム / セキュア / ネットワーク / 異常検知 / 処理時間推定 / 異常原因特定 / 不正利用ソフトウエア / 相関係数発生確率行列 / ホスト単位観測 / 順位相関係数 |
Research Abstract |
A network anomaly detection system has been developed. This system can achieve high detection accuracy by using feature values extracted with plural algorithms from network flows of which packets are aggregated based on their IP addresses and port numbers. The system can higher detection rate with feature values collected from distributed observation points.
|
Report
(4 results)
Research Products
(18 results)