Estimation of Increase of Scanners Based on ISDAS Distributed Sensors
スポンサーリンク
概要
- 論文の詳細を見る
Given independent multiple access logs, we develop a mathematical model to identify the number of malicious hosts in the current Internet. In our model, the number of malicious hosts is formalized as a function taking two inputs, namely the duration of observation and the number of sensors. Assuming that malicious hosts with statically assigned global addresses perform random port scans to independent sensors uniformly distributed over the address space, our model gives the asymptotic number of malicious source addresses in two ways. Firstly, it gives the cumulative number of unique source addresses in terms of the duration of observation. Secondly, it estimates the cumulative number of unique source addresses in terms of the number of sensors. To evaluate the proposed method, we apply the mathematical model to actual data packets observed by ISDAS distributed sensors over a one-year duration from September 2004, and check the accuracy of identification of the number of malicious hosts.
- Information and Media Technologies 編集運営会議の論文
著者
-
Terada Masato
Hitachi Incident Response Team (hirt) Hitachi Ltd.
-
Kikuchi Hiroaki
School Of Science And Technology Tokai University
-
Doi Norihisa
Facility of Science and Engineering, Chuo University
-
Fukuno Naoya
School of Information Technology, Tokai University
-
Kikuchi Hiroaki
School of Information Technology, Tokai University
関連論文
- Frequent Sequential Attack Patterns of Malware in Botnets
- Principal Component Analysis of Botnet Takeover
- Estimation of Increase of Scanners Based on ISDAS Distributed Sensors
- Analysis on the Sequential Behavior of Malware Attacks
- Principal Component Analysis of Botnet Takeover
- Time Zone Correlation Analysis of Malware/Bot Downloads
- Automated Port-scan Classification with Decision Tree and Distributed Sensors
- Mining Botnet Coordinated Attacks using Apriori-PrefixSpan Hybrid Algorithm
- Mining Botnet Coordinated Attacks using Apriori-PrefixSpan Hybrid Algorithm
- Estimation of Increase of Scanners Based on ISDAS Distributed Sensors
- Time Zone Analysis on IIJ Network Traffic for Malicious Botnet Activities