Internet Threat Detection System Using Bayesian Estimation

No ratings

Presented at First 2004 by

We present an Internet security threat detection system using Bayesian estimation method. This system analyzes security state of the Internet using Bayesian estimation with transition of frequencies of IP packet arrival events to some specified IP addresses such as port scanning, worm activities and so on. While the system calculates the frequency of access events in each time interval, Bayesian updating has been repeatedly applied to improve the confidence in degree of Internet critical states. When the system detects security threat(s) on the Internet, a security alert message is automatically sent to registered E-mail addresses, such as system administrators', and the system issues security alert details on our Web site. We also provide compact HTML and HDML for mobile phone browsers aka NTT DoCoMo's i-mode and KDDI's EZweb. Since the security state of the Internet changes dynamically, application of Bayesian estimation for threat detection is considered suitable because parameters of the model of Bayesian estimation are considered as dynamically changing quantities. This paper is focused on mechanism of detecting security threat using Bayesian estimation and our experimental evaluation. Some knoweldge on TCP/IP network technologies and statisics are required for this presentation. The intended audience of this paper presentation are network experts, network security researchers, system administrators, and data analysis researchers.