WEKO3
アイテム
{"_buckets": {"deposit": "a44c3a4b-b45f-4cfe-a64e-6bb593c007d6"}, "_deposit": {"created_by": 14, "id": "5096", "owners": [14], "pid": {"revision_id": 0, "type": "depid", "value": "5096"}, "status": "published"}, "_oai": {"id": "oai:kyutech.repo.nii.ac.jp:00005096", "sets": ["24"]}, "author_link": ["20529", "20530", "20531", "5853", "900"], "item_21_biblio_info_6": {"attribute_name": "書誌情報", "attribute_value_mlt": [{"bibliographicIssueDates": {"bibliographicIssueDate": "2012-07-01", "bibliographicIssueDateType": "Issued"}, "bibliographicIssueNumber": "7", "bibliographicPageEnd": "2367", "bibliographicPageStart": "2358", "bibliographicVolumeNumber": "E95-B", "bibliographic_titles": [{"bibliographic_title": "IEICE Transactions on Communications", "bibliographic_titleLang": "en"}]}]}, "item_21_description_4": {"attribute_name": "抄録", "attribute_value_mlt": [{"subitem_description": "We propose an anomaly detection method for finding patterns in network traffic that do not conform to legitimate (i.e., normal) behavior. The proposed method trains a baseline model describing the normal behavior of network traffic without using manually labeled traffic data. The trained baseline model is used as the basis for comparison with the audit network traffic. This anomaly detection works in an unsupervised manner through the use of time-periodic packet sampling, which is used in a manner that differs from its intended purpose — the lossy nature of packet sampling is used to extract normal packets from the unlabeled original traffic data. Evaluation using actual traffic traces showed that the proposed method has false positive and false negative rates in the detection of anomalies regarding TCP SYN packets comparable to those of a conventional method that uses manually labeled traffic data to train the baseline model. Performance variation due to the probabilistic nature of sampled traffic data is mitigated by using ensemble anomaly detection that collectively exploits multiple baseline models in parallel. Alarm sensitivity is adjusted for the intended use by using maximum- and minimum-based anomaly detection that effectively take advantage of the performance variations among the multiple baseline models. Testing using actual traffic traces showed that the proposed anomaly detection method performs as well as one using manually labeled traffic data and better than one using randomly sampled (unlabeled) traffic data. ", "subitem_description_language": "en", "subitem_description_type": "Abstract"}]}, "item_21_description_60": {"attribute_name": "資源タイプ", "attribute_value_mlt": [{"subitem_description": "Journal Article", "subitem_description_type": "Other"}]}, "item_21_publisher_7": {"attribute_name": "出版社", "attribute_value_mlt": [{"subitem_publisher": "電子情報通信学会", "subitem_publisher_language": "ja"}]}, "item_21_relation_12": {"attribute_name": "DOI", "attribute_value_mlt": [{"subitem_relation_type": "isIdenticalTo", "subitem_relation_type_id": {"subitem_relation_type_id_text": "https://doi.org/10.1587/transcom.E95.B.2358", "subitem_relation_type_select": "DOI"}}]}, "item_21_rights_13": {"attribute_name": "著作権関連情報", "attribute_value_mlt": [{"subitem_rights": "Copyright (c) 2012 The Institute of Electronics, Information and Communication Engineers"}]}, "item_21_select_59": {"attribute_name": "査読の有無", "attribute_value_mlt": [{"subitem_select_item": "yes"}]}, "item_21_source_id_10": {"attribute_name": "NCID", "attribute_value_mlt": [{"subitem_source_identifier": "AA10826261", "subitem_source_identifier_type": "NCID"}]}, "item_21_source_id_8": {"attribute_name": "ISSN", "attribute_value_mlt": [{"subitem_source_identifier": "0916-8516", "subitem_source_identifier_type": "PISSN"}, {"subitem_source_identifier": "1745-1345", "subitem_source_identifier_type": "EISSN"}]}, "item_21_text_63": {"attribute_name": "連携ID", "attribute_value_mlt": [{"subitem_text_value": "6280"}]}, "item_21_version_type_58": {"attribute_name": "出版タイプ", "attribute_value_mlt": [{"subitem_version_resource": "http://purl.org/coar/version/c_970fb48d4fbd8a85", "subitem_version_type": "VoR"}]}, "item_creator": {"attribute_name": "著者", "attribute_type": "creator", "attribute_value_mlt": [{"creatorNames": [{"creatorName": "Uchida, Masato", "creatorNameLang": "en"}], "nameIdentifiers": [{"nameIdentifier": "20529", "nameIdentifierScheme": "WEKO"}]}, {"creatorNames": [{"creatorName": "Nawata, Shuichi", "creatorNameLang": "en"}], "nameIdentifiers": [{"nameIdentifier": "20530", "nameIdentifierScheme": "WEKO"}]}, {"creatorNames": [{"creatorName": "Gu, Yu", "creatorNameLang": "en"}], "nameIdentifiers": [{"nameIdentifier": "20531", "nameIdentifierScheme": "WEKO"}]}, {"creatorAffiliations": [{"affiliationNames": [{"affiliationNameLang": "ja"}]}], "creatorNames": [{"creatorName": "Tsuru, Masato", "creatorNameLang": "en"}, {"creatorName": "鶴, 正人", "creatorNameLang": "ja"}, {"creatorName": "ツル, マサト", "creatorNameLang": "ja-Kana"}], "familyNames": [{"familyName": "Tsuru", "familyNameLang": "en"}, {"familyName": "鶴", "familyNameLang": "ja"}, {"familyName": "ツル", "familyNameLang": "ja-Kana"}], "givenNames": [{"givenName": "Masato", "givenNameLang": "en"}, {"givenName": "正人", "givenNameLang": "ja"}, {"givenName": "マサト", "givenNameLang": "ja-Kana"}], "nameIdentifiers": [{"nameIdentifier": "5853", "nameIdentifierScheme": "WEKO"}, {"nameIdentifier": "40231443", "nameIdentifierScheme": "e-Rad", "nameIdentifierURI": "https://nrid.nii.ac.jp/ja/nrid/1000040231443"}, {"nameIdentifier": "7005093872", "nameIdentifierScheme": "Scopus著者ID", "nameIdentifierURI": "https://www.scopus.com/authid/detail.uri?authorId=7005093872"}, {"nameIdentifier": "0000-0001-7340-6798", "nameIdentifierScheme": "ORCiD", "nameIdentifierURI": "https://orcid.org/0000-0001-7340-6798"}, {"nameIdentifier": "206", "nameIdentifierScheme": "九工大研究者情報", "nameIdentifierURI": "https://hyokadb02.jimu.kyutech.ac.jp/html/206_ja.html"}]}, {"creatorAffiliations": [{"affiliationNames": [{"affiliationNameLang": "ja"}]}], "creatorNames": [{"creatorName": "Oie, Yuji", "creatorNameLang": "en"}, {"creatorName": "尾家, 祐二", "creatorNameLang": "ja"}, {"creatorName": "オイエ, ユウジ", "creatorNameLang": "ja-Kana"}], "familyNames": [{"familyName": "Oie", "familyNameLang": "en"}, {"familyName": "尾家", "familyNameLang": "ja"}, {"familyName": "オイエ", "familyNameLang": "ja-Kana"}], "givenNames": [{"givenName": "Yuji", "givenNameLang": "en"}, {"givenName": "祐二", "givenNameLang": "ja"}, {"givenName": "ユウジ", "givenNameLang": "ja-Kana"}], "nameIdentifiers": [{"nameIdentifier": "900", "nameIdentifierScheme": "WEKO"}, {"nameIdentifier": "50167293", "nameIdentifierScheme": "e-Rad", "nameIdentifierURI": "https://nrid.nii.ac.jp/ja/nrid/1000050167293"}, {"nameIdentifier": "7006613491", "nameIdentifierScheme": "Scopus著者ID", "nameIdentifierURI": "https://www.scopus.com/authid/detail.uri?authorId=7006613491"}]}]}, "item_files": {"attribute_name": "ファイル情報", "attribute_type": "file", "attribute_value_mlt": [{"accessrole": "open_date", "date": [{"dateType": "Available", "dateValue": "2017-08-24"}], "displaytype": "detail", "download_preview_message": "", "file_order": 0, "filename": "ieice_t_c_95_7.pdf", "filesize": [{"value": "985.0 kB"}], "format": "application/pdf", "future_date_message": "", "is_thumbnail": false, "licensetype": "license_note", "mimetype": "application/pdf", "size": 985000.0, "url": {"label": "ieice_t_c_95_7.pdf", "url": "https://kyutech.repo.nii.ac.jp/record/5096/files/ieice_t_c_95_7.pdf"}, "version_id": "e4938d74-f320-4863-b9d3-61750e331574"}]}, "item_keyword": {"attribute_name": "キーワード", "attribute_value_mlt": [{"subitem_subject": "anomaly detection", "subitem_subject_scheme": "Other"}, {"subitem_subject": "packet sampling", "subitem_subject_scheme": "Other"}]}, "item_language": {"attribute_name": "言語", "attribute_value_mlt": [{"subitem_language": "eng"}]}, "item_resource_type": {"attribute_name": "資源タイプ", "attribute_value_mlt": [{"resourcetype": "journal article", "resourceuri": "http://purl.org/coar/resource_type/c_6501"}]}, "item_title": "Unsupervised Ensemble Anomaly Detection Using Time-Periodic Packet Sampling", "item_titles": {"attribute_name": "タイトル", "attribute_value_mlt": [{"subitem_title": "Unsupervised Ensemble Anomaly Detection Using Time-Periodic Packet Sampling", "subitem_title_language": "en"}]}, "item_type_id": "21", "owner": "14", "path": ["24"], "permalink_uri": "http://hdl.handle.net/10228/00006308", "pubdate": {"attribute_name": "PubDate", "attribute_value": "2017-08-24"}, "publish_date": "2017-08-24", "publish_status": "0", "recid": "5096", "relation": {}, "relation_version_is_last": true, "title": ["Unsupervised Ensemble Anomaly Detection Using Time-Periodic Packet Sampling"], "weko_shared_id": -1}
Unsupervised Ensemble Anomaly Detection Using Time-Periodic Packet Sampling
http://hdl.handle.net/10228/00006308
http://hdl.handle.net/10228/00006308c01f5e11-7f0d-4da3-877d-d3b94af87a54
名前 / ファイル | ライセンス | アクション |
---|---|---|
ieice_t_c_95_7.pdf (985.0 kB)
|
|
Item type | 学術雑誌論文 = Journal Article(1) | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|
公開日 | 2017-08-24 | |||||||||||
資源タイプ | ||||||||||||
資源タイプ識別子 | http://purl.org/coar/resource_type/c_6501 | |||||||||||
資源タイプ | journal article | |||||||||||
タイトル | ||||||||||||
言語 | en | |||||||||||
タイトル | Unsupervised Ensemble Anomaly Detection Using Time-Periodic Packet Sampling | |||||||||||
言語 | ||||||||||||
言語 | eng | |||||||||||
著者 |
Uchida, Masato
× Uchida, Masato× Nawata, Shuichi× Gu, Yu× 鶴, 正人
WEKO
5853
× 尾家, 祐二 |
|||||||||||
抄録 | ||||||||||||
内容記述タイプ | Abstract | |||||||||||
内容記述 | We propose an anomaly detection method for finding patterns in network traffic that do not conform to legitimate (i.e., normal) behavior. The proposed method trains a baseline model describing the normal behavior of network traffic without using manually labeled traffic data. The trained baseline model is used as the basis for comparison with the audit network traffic. This anomaly detection works in an unsupervised manner through the use of time-periodic packet sampling, which is used in a manner that differs from its intended purpose — the lossy nature of packet sampling is used to extract normal packets from the unlabeled original traffic data. Evaluation using actual traffic traces showed that the proposed method has false positive and false negative rates in the detection of anomalies regarding TCP SYN packets comparable to those of a conventional method that uses manually labeled traffic data to train the baseline model. Performance variation due to the probabilistic nature of sampled traffic data is mitigated by using ensemble anomaly detection that collectively exploits multiple baseline models in parallel. Alarm sensitivity is adjusted for the intended use by using maximum- and minimum-based anomaly detection that effectively take advantage of the performance variations among the multiple baseline models. Testing using actual traffic traces showed that the proposed anomaly detection method performs as well as one using manually labeled traffic data and better than one using randomly sampled (unlabeled) traffic data. | |||||||||||
言語 | en | |||||||||||
書誌情報 |
en : IEICE Transactions on Communications 巻 E95-B, 号 7, p. 2358-2367, 発行日 2012-07-01 |
|||||||||||
出版社 | ||||||||||||
言語 | ja | |||||||||||
出版者 | 電子情報通信学会 | |||||||||||
DOI | ||||||||||||
関連タイプ | isIdenticalTo | |||||||||||
識別子タイプ | DOI | |||||||||||
関連識別子 | https://doi.org/10.1587/transcom.E95.B.2358 | |||||||||||
NCID | ||||||||||||
収録物識別子タイプ | NCID | |||||||||||
収録物識別子 | AA10826261 | |||||||||||
ISSN | ||||||||||||
収録物識別子タイプ | PISSN | |||||||||||
収録物識別子 | 0916-8516 | |||||||||||
ISSN | ||||||||||||
収録物識別子タイプ | EISSN | |||||||||||
収録物識別子 | 1745-1345 | |||||||||||
著作権関連情報 | ||||||||||||
権利情報 | Copyright (c) 2012 The Institute of Electronics, Information and Communication Engineers | |||||||||||
キーワード | ||||||||||||
主題Scheme | Other | |||||||||||
主題 | anomaly detection | |||||||||||
キーワード | ||||||||||||
主題Scheme | Other | |||||||||||
主題 | packet sampling | |||||||||||
出版タイプ | ||||||||||||
出版タイプ | VoR | |||||||||||
出版タイプResource | http://purl.org/coar/version/c_970fb48d4fbd8a85 | |||||||||||
査読の有無 | ||||||||||||
値 | yes | |||||||||||
連携ID | ||||||||||||
6280 | ||||||||||||
資料タイプ | ||||||||||||
内容記述タイプ | Other | |||||||||||
内容記述 | Journal Article |