International Journal of the Society of Materials Engineering for Resources
Online ISSN : 1884-6629
Print ISSN : 1347-9725
ISSN-L : 1347-9725
ICMR2009 AKITA II Originals
Network Anomaly Detection Based on R/S Pox Diagram
Akinori TAKAHASHIRyuji IGARASHIHiroshi UEDAYukio IWAYATetsuo KINOSHITA
著者情報
ジャーナル フリー

2010 年 17 巻 2 号 p. 186-192

詳細
抄録

A method is proposed in this paper to detect attack traffic or anomaly by utilizing an R/S analysis. Our study so far indicates that a LS(Level Shift) or a Cycle superimposed on a discrete time series provides a dispersion in the R/S pox diagram. The LS is well expressed by both HSup and HInf, the slope of the upper- and the lower-most plots group of the pox diagram. By utilizing them as the indices of the anomaly traffic, the validity of our proposal is tested at first by a Bernoulli trial simulation and then with the traffic data of "1999 DARPA Intrusion Detection Evaluation Data Set". Tested attacks are TCP SYN Flood, UDP Storm, and Smurf and our investigations showed that HInf may become a promising parameter for the detection of flooding attacks.

著者関連情報
© 2010 The Society of Materials Engineering for Resources of Japan
前の記事 次の記事
feedback
Top