• DocumentCode
    2918748
  • Title

    A SOC Framework for ISP Federation and Attack Forecast by Learning Propagation Patterns

  • Author

    Takemori, Keisuke ; Miyake, Yutaka ; Ishida, Chie ; Sasase, Iwao

  • Author_Institution
    KDDI R&D Labs., Kamifukuoka
  • fYear
    2007
  • fDate
    23-24 May 2007
  • Firstpage
    172
  • Lastpage
    179
  • Abstract
    A security operation center (SOC), which monitors network traffic on each domain, has been established to detect cyber attacks. However, there have been ever increasing worms and distributed denial of service (DDoS) attacks on the Internet and the number of unknown attacks is increasing day by day. It is hard to defend network infrastructure via the SOC, which is operated by an internet service provider (ISP). It is thus important to predict new security threats and share incidents that occur with related ISPs. In the case of Japan, the Telecom Information Sharing and Analysis Center (Telecom-ISAC) Japan is established for a federation scheme with ISP operators against serious security incidents. In this research, we design a federation SOC framework that monitors wide-area networks and analyzes multi-point traffic using statistical approaches. It can suggest anomalous ISPs and traffic parameters automatically. Moreover, we propose an attack forecast technique to ensure a swift response to regular and new attacks. The technique depicts an attack map and learns attack propagation patterns by using the Bayesian inference. We implement the system and evaluate integrated scale of the ISPs and forecast correct rate.
  • Keywords
    Bayes methods; Internet; inference mechanisms; security of data; telecommunication security; telecommunication traffic; Bayesian inference; Internet service provider federation scheme; Telecom-ISAC; cyber attack detection; distributed denial of service attack; network traffic; security operation center framework; wide-area network; Bayesian methods; Computer crime; Computer security; Data security; IP networks; Information analysis; Information security; Probes; Telecommunication traffic; Web and internet services;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Intelligence and Security Informatics, 2007 IEEE
  • Conference_Location
    New Brunswick, NJ
  • Electronic_ISBN
    1-4244-1329-X
  • Type

    conf

  • DOI
    10.1109/ISI.2007.379551
  • Filename
    4258692