The Experts below are selected from a list of 1305 Experts worldwide ranked by ideXlab platform
Toshinori Sueyoshi - One of the best experts on this subject based on the ideXlab platform.
-
The Evaluation of an Anomaly Detection System Based on Chi-square Method
2012 26th International Conference on Advanced Information Networking and Applications Workshops, 2012Co-Authors: Shunsuke Oshima, Takuo Nakashima, Toshinori SueyoshiAbstract:The conventional methods using X2 value have been proposed to detect anomaly attacks. These systems, however, merely treat the one feature such as the source IP address or the Destination Port number as the probabilistic variable. The method based on multiple variables has not been proposed to aim to improve the accuracy of anomaly detection. In this paper, we propose the multiple features X2 method named the CSDM (Chi-square-based Space Division Method) to improve the detection accuracy. The F-measure values of CSDM and the conventional method are compared to evaluate these systems. We also focus on the learning mechanism and it's affection for both systems. As the results of experiments using the source IP address, the Destination Port number, and the interval time deviation of arriving packets as the probabilistic variables, the proposed CSDM improves the F-measure compared to the conventional method meaning that the CSDM using multiple features can improve the F-measure over DoS/DDoS attacks and double attacks with 30$\%$ attacking rate. In addition, the learning time of the 2 days in the CSDM system is enough to learn the behavior of normal condition and can reveal the quick learning performance with the high F-measures.
-
AINA Workshops - The Evaluation of an Anomaly Detection System Based on Chi-square Method
2012 26th International Conference on Advanced Information Networking and Applications Workshops, 2012Co-Authors: Shunsuke Oshima, Takuo Nakashima, Toshinori SueyoshiAbstract:The conventional methods using $\chi^2$ value have been proposed to detect anomaly attacks. These systems, however, merely treat the one feature such as the source IP address or the Destination Port number as the probabilistic variable. The method based on multiple variables has not been proposed to aim to improve the accuracy of anomaly detection. In this paper, we propose the multiple features $\chi^{2}$ method named the CSDM (Chi-square-based Space Division Method) to improve the detection accuracy. The F-measure values of CSDM and the conventional method are compared to evaluate these systems. We also focus on the learning mechanism and it's affection for both systems. As the results of experiments using the source IP address, the Destination Port number, and the interval time deviation of arriving packets as the probabilistic variables, the proposed CSDM improves the F-measure compared to the conventional method meaning that the CSDM using multiple features can improve the F-measure over DoS/DDoS attacks and double attacks with 30$\%$ attacking rate. In addition, the learning time of the 2 days in the CSDM system is enough to learn the behavior of normal condition and can reveal the quick learning@performance with the high F-measures.
-
NBiS - Comparison of Properties between Entropy and Chi-Square Based Anomaly Detection Method
2011 14th International Conference on Network-Based Information Systems, 2011Co-Authors: Shunsuke Oshima, Takuo Nakashima, Toshinori SueyoshiAbstract:As the typical anomaly detection methods using statistics, entropy and chi-square based method has been researched and rePorted in terms of their properties for anomaly attacks. In this research, we compare the properties of both methods and discuss the accuracy of detection and the efficiency for different kinds of attacks. Our previous researches have clarified that the source IP address and Destination Port number are efficient statistical variables to view the anomaly packet property, which lead to detect correctly. In this paper, we propose EMMM method for entropy value and CSDM method of chi-square value using multi statistical variables. The experiments to verify our proposed methods were conducted using source IP address, Destination Port number and arriving interval of packets. We could extract the following results. Firstly, EMMM method could decrease the value of False-Positive and False-Negative. Secondly, CSDM method could increase the F-metric, which is the evaluation standard for accurate detection. In the experiments using the same condition of parameters such as probability valuables and window width, CSDM method enlarges the F-metric compared to EMMM method.
-
Anomaly Detection Using Chi-square Values Based on the Typical Features and the Time Deviation
2011 IEEE International Conference on Advanced Information Networking and Applications, 2011Co-Authors: Shunsuke Oshima, Takuo Nakashima, Toshinori SueyoshiAbstract:In the research of the anomaly detection system analyzing the packet header on the Internet, previous researches have proposed the anomaly detection system using chi-square values in terms of the source IP address and/or the Destination Port number. In these previous researches, the chi-square values were calculated from one feature causing the degradation in the False-Positive when the same symbol appears sequentially. Therefore, we propose the anomaly detection technique using chi-square values based on multi features. We also propose dynamic BIN division technique to deal with the traffic fluctuations such as day and night traffic differences. Applying our method, the chi-square values based on the time division were able to decrease the False-Positive. Our method was also able to adapt the traffic variations by applying the dynamic BIN division technique.
-
Comparison of Properties between Entropy and Chi-Square Based Anomaly Detection Method
2011 14th International Conference on Network-Based Information Systems, 2011Co-Authors: Shunsuke Oshima, Takuo Nakashima, Toshinori SueyoshiAbstract:As the typical anomaly detection methods using statistics, entropy and χ2 based method has been researched and rePorted in terms of their properties for anomaly attacks. In this research, we compare the properties of both methods and discuss the accuracy of detection and the efficiency for different kinds of attacks. Our previous researches have clarified that the source IP address and Destination Port number are efficient statistical variables to view the anomaly packet property, which lead to detect correctly. In this paper, we propose EMMM method for entropy value and CSDM method of χ2 value using multi statistical variables. The experiments to verify our proposed methods were conducted using source IP address, Destination Port number and arriving interval of packets. We could extract the following results. Firstly, EMMM method could decrease the value of False-Positive and False-Negative. Secondly, CSDM method could increase the F-metric, which is the evaluation standard for accurate detection. In the experiments using the same condition of parameters such as probability valuables and window width, CSDM method enlarges the F-metric compared to EMMM method.
Shunsuke Oshima - One of the best experts on this subject based on the ideXlab platform.
-
BWCCA - Computational Complexity of Anomaly Detection Methods
2012 Seventh International Conference on Broadband Wireless Computing Communication and Applications, 2012Co-Authors: Shunsuke Oshima, Takuo NakashimaAbstract:As the typical anomaly detection methods using statistics, entropy and $\chi^2$ based method has been researched and rePorted with their performance properties for anomaly attacks. In this research, we compare the time complexity of two our proposed detection method aiming to evaluate the performance of our system. Our previous researches have clarified that the source IP address and Destination Port number are efficient statistical variables to view the anomaly packet property, which lead to detect correctly. In this paper, we propose EMMM method for entropy value and CSDM method of $\chi^2$ value using multi statistical variables. The evaluation to verify the time complexity of our proposed methods were conducted using source IP address, Destination Port number and arriving interval of packets. We could extract the following results. Firstly, the total time complexity of the EMMM method is $O(n)$ for the $n$ total packets, and the time complexity of one window is $O(W)$. Secondly, the time complexity of CSDM for one window is $O(NW+Nm\log m)$.
-
The Evaluation of an Anomaly Detection System Based on Chi-square Method
2012 26th International Conference on Advanced Information Networking and Applications Workshops, 2012Co-Authors: Shunsuke Oshima, Takuo Nakashima, Toshinori SueyoshiAbstract:The conventional methods using X2 value have been proposed to detect anomaly attacks. These systems, however, merely treat the one feature such as the source IP address or the Destination Port number as the probabilistic variable. The method based on multiple variables has not been proposed to aim to improve the accuracy of anomaly detection. In this paper, we propose the multiple features X2 method named the CSDM (Chi-square-based Space Division Method) to improve the detection accuracy. The F-measure values of CSDM and the conventional method are compared to evaluate these systems. We also focus on the learning mechanism and it's affection for both systems. As the results of experiments using the source IP address, the Destination Port number, and the interval time deviation of arriving packets as the probabilistic variables, the proposed CSDM improves the F-measure compared to the conventional method meaning that the CSDM using multiple features can improve the F-measure over DoS/DDoS attacks and double attacks with 30$\%$ attacking rate. In addition, the learning time of the 2 days in the CSDM system is enough to learn the behavior of normal condition and can reveal the quick learning performance with the high F-measures.
-
AINA Workshops - The Evaluation of an Anomaly Detection System Based on Chi-square Method
2012 26th International Conference on Advanced Information Networking and Applications Workshops, 2012Co-Authors: Shunsuke Oshima, Takuo Nakashima, Toshinori SueyoshiAbstract:The conventional methods using $\chi^2$ value have been proposed to detect anomaly attacks. These systems, however, merely treat the one feature such as the source IP address or the Destination Port number as the probabilistic variable. The method based on multiple variables has not been proposed to aim to improve the accuracy of anomaly detection. In this paper, we propose the multiple features $\chi^{2}$ method named the CSDM (Chi-square-based Space Division Method) to improve the detection accuracy. The F-measure values of CSDM and the conventional method are compared to evaluate these systems. We also focus on the learning mechanism and it's affection for both systems. As the results of experiments using the source IP address, the Destination Port number, and the interval time deviation of arriving packets as the probabilistic variables, the proposed CSDM improves the F-measure compared to the conventional method meaning that the CSDM using multiple features can improve the F-measure over DoS/DDoS attacks and double attacks with 30$\%$ attacking rate. In addition, the learning time of the 2 days in the CSDM system is enough to learn the behavior of normal condition and can reveal the quick learning@performance with the high F-measures.
-
Computational Complexity of Anomaly Detection Methods
2012 Seventh International Conference on Broadband Wireless Computing Communication and Applications, 2012Co-Authors: Shunsuke Oshima, Takuo NakashimaAbstract:As the typical anomaly detection methods using statistics, entropy and χ2 based method has been researched and rePorted with their performance properties for anomaly attacks. In this research, we compare the time complexity of two our proposed detection method aiming to evaluate the performance of our system. Our previous researches have clarified that the source IP address and Destination Port number are efficient statistical variables to view the anomaly packet property, which lead to detect correctly. In this paper, we propose EMMM method for entropy value and CSDM method of χ2 value using multi statistical variables. The evaluation to verify the time complexity of our proposed methods were conducted using source IP address, Destination Port number and arriving interval of packets. We could extract the following results. Firstly, the total time complexity of the EMMM method is O(n) for the n total packets, and the time complexity of one window is O(W). Secondly, the time complexity of CSDM for one window is O(NW + Nm log m).
-
NBiS - Comparison of Properties between Entropy and Chi-Square Based Anomaly Detection Method
2011 14th International Conference on Network-Based Information Systems, 2011Co-Authors: Shunsuke Oshima, Takuo Nakashima, Toshinori SueyoshiAbstract:As the typical anomaly detection methods using statistics, entropy and chi-square based method has been researched and rePorted in terms of their properties for anomaly attacks. In this research, we compare the properties of both methods and discuss the accuracy of detection and the efficiency for different kinds of attacks. Our previous researches have clarified that the source IP address and Destination Port number are efficient statistical variables to view the anomaly packet property, which lead to detect correctly. In this paper, we propose EMMM method for entropy value and CSDM method of chi-square value using multi statistical variables. The experiments to verify our proposed methods were conducted using source IP address, Destination Port number and arriving interval of packets. We could extract the following results. Firstly, EMMM method could decrease the value of False-Positive and False-Negative. Secondly, CSDM method could increase the F-metric, which is the evaluation standard for accurate detection. In the experiments using the same condition of parameters such as probability valuables and window width, CSDM method enlarges the F-metric compared to EMMM method.
Takuo Nakashima - One of the best experts on this subject based on the ideXlab platform.
-
Detection System for Anomaly Attacks using Statistical Methods
Proceedings of The 2nd International Conference on Intelligent Systems and Image Processing 2014, 2014Co-Authors: Takuo NakashimaAbstract:The computer systems connected to the Internet are exposed the threats of DoS/DDoS attacks aiming to destroy the server functions. The malicious users hijack the vulnerable PCs and generate the attacking PCs called as BOT. A large number of BOTs sends a huge number of anomaly packets to paralyze the server functions. The early detection methods for these anomaly packets are required to sustain the damage of DoS/DDoS attacks. Our previous researches have clarified that the source IP address and Destination Port number are efficient statistical variables to view the anomaly packet property. In this speech, we show EMMM (Entropy-based Multidimensional Mahalanobis-distance Method) method for entropy value and CSDM (χ square based Space Division Method) method for χ square value using multi statistical variables. The experiments to verify our two proposed methods were conducted using source IP address, Destination Port number and arriving interval of packets. We could extract the following results. Firstly, EMMM could decrease the value of False-Positive and False-Negative. Secondly, CSDM could increase the F-metric. In the experiments using the same condition of parameters such as probability valuables and window width, CSDM enlarges the F-metric compared to EMMM.
-
BWCCA - Computational Complexity of Anomaly Detection Methods
2012 Seventh International Conference on Broadband Wireless Computing Communication and Applications, 2012Co-Authors: Shunsuke Oshima, Takuo NakashimaAbstract:As the typical anomaly detection methods using statistics, entropy and $\chi^2$ based method has been researched and rePorted with their performance properties for anomaly attacks. In this research, we compare the time complexity of two our proposed detection method aiming to evaluate the performance of our system. Our previous researches have clarified that the source IP address and Destination Port number are efficient statistical variables to view the anomaly packet property, which lead to detect correctly. In this paper, we propose EMMM method for entropy value and CSDM method of $\chi^2$ value using multi statistical variables. The evaluation to verify the time complexity of our proposed methods were conducted using source IP address, Destination Port number and arriving interval of packets. We could extract the following results. Firstly, the total time complexity of the EMMM method is $O(n)$ for the $n$ total packets, and the time complexity of one window is $O(W)$. Secondly, the time complexity of CSDM for one window is $O(NW+Nm\log m)$.
-
The Evaluation of an Anomaly Detection System Based on Chi-square Method
2012 26th International Conference on Advanced Information Networking and Applications Workshops, 2012Co-Authors: Shunsuke Oshima, Takuo Nakashima, Toshinori SueyoshiAbstract:The conventional methods using X2 value have been proposed to detect anomaly attacks. These systems, however, merely treat the one feature such as the source IP address or the Destination Port number as the probabilistic variable. The method based on multiple variables has not been proposed to aim to improve the accuracy of anomaly detection. In this paper, we propose the multiple features X2 method named the CSDM (Chi-square-based Space Division Method) to improve the detection accuracy. The F-measure values of CSDM and the conventional method are compared to evaluate these systems. We also focus on the learning mechanism and it's affection for both systems. As the results of experiments using the source IP address, the Destination Port number, and the interval time deviation of arriving packets as the probabilistic variables, the proposed CSDM improves the F-measure compared to the conventional method meaning that the CSDM using multiple features can improve the F-measure over DoS/DDoS attacks and double attacks with 30$\%$ attacking rate. In addition, the learning time of the 2 days in the CSDM system is enough to learn the behavior of normal condition and can reveal the quick learning performance with the high F-measures.
-
AINA Workshops - The Evaluation of an Anomaly Detection System Based on Chi-square Method
2012 26th International Conference on Advanced Information Networking and Applications Workshops, 2012Co-Authors: Shunsuke Oshima, Takuo Nakashima, Toshinori SueyoshiAbstract:The conventional methods using $\chi^2$ value have been proposed to detect anomaly attacks. These systems, however, merely treat the one feature such as the source IP address or the Destination Port number as the probabilistic variable. The method based on multiple variables has not been proposed to aim to improve the accuracy of anomaly detection. In this paper, we propose the multiple features $\chi^{2}$ method named the CSDM (Chi-square-based Space Division Method) to improve the detection accuracy. The F-measure values of CSDM and the conventional method are compared to evaluate these systems. We also focus on the learning mechanism and it's affection for both systems. As the results of experiments using the source IP address, the Destination Port number, and the interval time deviation of arriving packets as the probabilistic variables, the proposed CSDM improves the F-measure compared to the conventional method meaning that the CSDM using multiple features can improve the F-measure over DoS/DDoS attacks and double attacks with 30$\%$ attacking rate. In addition, the learning time of the 2 days in the CSDM system is enough to learn the behavior of normal condition and can reveal the quick learning@performance with the high F-measures.
-
Computational Complexity of Anomaly Detection Methods
2012 Seventh International Conference on Broadband Wireless Computing Communication and Applications, 2012Co-Authors: Shunsuke Oshima, Takuo NakashimaAbstract:As the typical anomaly detection methods using statistics, entropy and χ2 based method has been researched and rePorted with their performance properties for anomaly attacks. In this research, we compare the time complexity of two our proposed detection method aiming to evaluate the performance of our system. Our previous researches have clarified that the source IP address and Destination Port number are efficient statistical variables to view the anomaly packet property, which lead to detect correctly. In this paper, we propose EMMM method for entropy value and CSDM method of χ2 value using multi statistical variables. The evaluation to verify the time complexity of our proposed methods were conducted using source IP address, Destination Port number and arriving interval of packets. We could extract the following results. Firstly, the total time complexity of the EMMM method is O(n) for the n total packets, and the time complexity of one window is O(W). Secondly, the time complexity of CSDM for one window is O(NW + Nm log m).
Graham Swift - One of the best experts on this subject based on the ideXlab platform.
-
simulation of an all optical time division multiplexing router employing symmetric mach zehnder smz
High Frequency Postgraduate Student Colloquium, 2002Co-Authors: Razali Ngah, Zabih Ghassemlooy, Graham SwiftAbstract:Synchronisation is an imPortant and critical issue in high-speed all optical time division multiplexed (OTDM) packet routing and transmission. In this paper we present a technique for separating the clock synchronization pulse from an incoming optical time division multiplexed data packet, based on all-optical switching devices with optical feedback. A 1/spl times/2 OTDM router composed of three symmetric Mach-Zehnders (SMZs) is proposed. Simulation results show that synchronization between clock and data packet is achievable and the packet payload can be successfully switched to the correct Destination Port.
-
Simulation of an all optical time division multiplexing router employing TOADs
2002Co-Authors: Razali Ngah, Graham Swift, Zabih Ghassemlooy, Tahir Ahmad, Peter BallAbstract:Synchronisation is an imPortant and critical issue in high-speed all optical time division multiplexed (OTDM) packet routing and transmission. In this paper we present a technique for separating the clock synchronization pulse from an incoming optical time division multiplexed data packet, based on all-optical switching devices with optical feedback. A 1X2 OTDM router composed of three Symmetric Mach-Zehnders (SMZs) is proposed. Simulation results show that synchronization between clock and data packet is achievable and the packet payload can be successfully switched to the correct Destination Port.
-
Simulation of an all optical time division multiplexing router employing Symmetric Mach-Zehnder (SMZ)
IEEE High Frequency Postgraduate Student Colloquium, 2002Co-Authors: Razali Ngah, Zabih Ghassemlooy, Graham SwiftAbstract:Synchronisation is an imPortant and critical issue in high-speed all optical time division multiplexed (OTDM) packet routing and transmission. In this paper we present a technique for separating the clock synchronization pulse from an incoming optical time division multiplexed data packet, based on all-optical switching devices with optical feedback. A 1X2 OTDM router composed of three Symmetric Mach-Zehnders (SMZs) is proposed. Simulation results show that synchronization between clock and data packet is achievable and the packet payload can be successfully switched to the correct Destination Port. © 2002 IEEE.
Razali Ngah - One of the best experts on this subject based on the ideXlab platform.
-
simulation of an all optical time division multiplexing router employing symmetric mach zehnder smz
High Frequency Postgraduate Student Colloquium, 2002Co-Authors: Razali Ngah, Zabih Ghassemlooy, Graham SwiftAbstract:Synchronisation is an imPortant and critical issue in high-speed all optical time division multiplexed (OTDM) packet routing and transmission. In this paper we present a technique for separating the clock synchronization pulse from an incoming optical time division multiplexed data packet, based on all-optical switching devices with optical feedback. A 1/spl times/2 OTDM router composed of three symmetric Mach-Zehnders (SMZs) is proposed. Simulation results show that synchronization between clock and data packet is achievable and the packet payload can be successfully switched to the correct Destination Port.
-
Simulation of an all optical time division multiplexing router employing TOADs
2002Co-Authors: Razali Ngah, Graham Swift, Zabih Ghassemlooy, Tahir Ahmad, Peter BallAbstract:Synchronisation is an imPortant and critical issue in high-speed all optical time division multiplexed (OTDM) packet routing and transmission. In this paper we present a technique for separating the clock synchronization pulse from an incoming optical time division multiplexed data packet, based on all-optical switching devices with optical feedback. A 1X2 OTDM router composed of three Symmetric Mach-Zehnders (SMZs) is proposed. Simulation results show that synchronization between clock and data packet is achievable and the packet payload can be successfully switched to the correct Destination Port.
-
Simulation of an all optical time division multiplexing router employing Symmetric Mach-Zehnder (SMZ)
IEEE High Frequency Postgraduate Student Colloquium, 2002Co-Authors: Razali Ngah, Zabih Ghassemlooy, Graham SwiftAbstract:Synchronisation is an imPortant and critical issue in high-speed all optical time division multiplexed (OTDM) packet routing and transmission. In this paper we present a technique for separating the clock synchronization pulse from an incoming optical time division multiplexed data packet, based on all-optical switching devices with optical feedback. A 1X2 OTDM router composed of three Symmetric Mach-Zehnders (SMZs) is proposed. Simulation results show that synchronization between clock and data packet is achievable and the packet payload can be successfully switched to the correct Destination Port. © 2002 IEEE.