Mining Botnet Coordinated Attacks using Apriori-PrefixSpan Hybrid Algorithm (Preprint)
スポンサーリンク
概要
- 論文の詳細を見る
This paper aims to detect features of coordinated attacks by applying data mining techniques, namely Apriori with PrefixSpan, to the CCC DATAset 2008-2010, which comprises captured packet data and downloading logs. Data mining algorithms enable us to automate the detection of characteristics in large amounts of data, which conventional heuristics cannot deal with. Apriori achieves a high recall but with false positives, whereas PrefixSpan has high precision but low recall. We therefore propose a hybrid of these two algorithms. Our analysis shows a change in the behavior of malware over the past three years.------------------------------This is a preprint of an article intended for publication Journal ofInformation Processing(JIP). This preprint should not be cited. Thisarticle should be cited as: Journal of Information Processing Vol.21(2013) No.4 (online)------------------------------
- 2013-09-15
著者
-
Masato Terada
Hitachi Ltd. Hitachi Incident Response Team (hirt)
-
Masayuki Ohrui
Tokai University
-
Masato Terada
Hitachi Ltd., Hitachi Incident Response Team (HIRT)
-
Hiroaki Kikuchi
Department of Frontier Media Science, School of Interdisciplinary Mathematical Sciences, Meiji University | School of Information and Telecommunication Engineering, Tokai University
-
Masayuki Ohrui
Hitachi Ltd., Security & Smart ID Solutions Division
-
Hiroaki Kikuchi
Department of Frontier Media Science, School of Interdisciplinary Mathematical Sciences, Meiji University
関連論文
- Principal Component Analysis of Port-scans for Reduction of Distributed Sensors
- Frequent Sequential Attack Patterns of Malware in Botnets
- Frequent Sequential Attack Patterns of Malware in Botnets
- Automated Port-scan Classification with Decision Tree and Distributed Sensors
- Estimation of Increase of Scanners Based on ISDAS Distributed Sensors
- Principal Component Analysis of Botnet Takeover
- Privacy-preserving Collaborative Filtering Using Randomized Response (Preprint)
- Mining Botnet Coordinated Attacks using Apriori-PrefixSpan Hybrid Algorithm (Preprint)
- Bloom Filter Bootstrap: Privacy-Preserving Estimation of the Size of an Intersection (Preprint)