ROOK: Multi-session based network security event detector

Masayoshi Mizutani, Shin Shirahata, Masaki Minami, Jun Murai

研究成果: Conference contribution

3 被引用数 (Scopus)

抄録

We have implemented Multi-Session based Network Security Event Detector: ROOK to detect botnet activity and P2P file sharing traffic and our results show that our method is less false positives than existing network security event detectors (e.g. IDS). We proposed a network security event detection method by analyzing correlation among multiple sessions. Our method can recognize hosts behaviors by rules that describe multi-session correlations: a rule includes the order of starting sessions and information exchange between sessions. By this method, ROOK detected DNS and IRC activities of bots in the experiment.

本文言語English
ホスト出版物のタイトルProceedings - 2008 International Symposium on Applications and the Internet, SAINT 2008
ページ48-54
ページ数7
DOI
出版ステータスPublished - 2008
イベント2008 International Symposium on Applications and the Internet, SAINT 2008 - Turku, Finland
継続期間: 2008 7月 282008 8月 1

出版物シリーズ

名前Proceedings - 2008 International Symposium on Applications and the Internet, SAINT 2008

Other

Other2008 International Symposium on Applications and the Internet, SAINT 2008
国/地域Finland
CityTurku
Period08/7/2808/8/1

ASJC Scopus subject areas

  • コンピュータ ネットワークおよび通信
  • コンピュータ サイエンスの応用

フィンガープリント

「ROOK: Multi-session based network security event detector」の研究トピックを掘り下げます。これらがまとまってユニークなフィンガープリントを構成します。

引用スタイル