The search functionality is under construction.

IEICE TRANSACTIONS on Information

Real-Time Detection of Global Cyberthreat Based on Darknet by Estimating Anomalous Synchronization Using Graphical Lasso

Chansu HAN, Jumpei SHIMAMURA, Takeshi TAKAHASHI, Daisuke INOUE, Jun'ichi TAKEUCHI, Koji NAKAO

  • Full Text Views

    0

  • Cite this

Summary :

With the rapid evolution and increase of cyberthreats in recent years, it is necessary to detect and understand it promptly and precisely to reduce the impact of cyberthreats. A darknet, which is an unused IP address space, has a high signal-to-noise ratio, so it is easier to understand the global tendency of malicious traffic in cyberspace than other observation networks. In this paper, we aim to capture global cyberthreats in real time. Since multiple hosts infected with similar malware tend to perform similar behavior, we propose a system that estimates a degree of synchronizations from the patterns of packet transmission time among the source hosts observed in unit time of the darknet and detects anomalies in real time. In our evaluation, we perform our proof-of-concept implementation of the proposed engine to demonstrate its feasibility and effectiveness, and we detect cyberthreats with an accuracy of 97.14%. This work is the first practical trial that detects cyberthreats from in-the-wild darknet traffic regardless of new types and variants in real time, and it quantitatively evaluates the result.

Publication
IEICE TRANSACTIONS on Information Vol.E103-D No.10 pp.2113-2124
Publication Date
2020/10/01
Publicized
2020/06/25
Online ISSN
1745-1361
DOI
10.1587/transinf.2020EDP7076
Type of Manuscript
PAPER
Category
Information Network

Authors

Chansu HAN
  National Institute of Information and Communications Technology,Kyushu University
Jumpei SHIMAMURA
  clwit Inc.
Takeshi TAKAHASHI
  National Institute of Information and Communications Technology
Daisuke INOUE
  National Institute of Information and Communications Technology
Jun'ichi TAKEUCHI
  Kyushu University
Koji NAKAO
  National Institute of Information and Communications Technology

Keyword