A Lightweight Abnormality Detection Mechanism by Stray Packets Analysis

Yong Jin, Satoshi Matsuura, Takao Kondo, Tatsumi Hosokawa, Masahiko Tomoishi

Research output: Chapter in Book/Report/Conference proceedingConference contribution

Abstract

An academic organization network, e.g., a campus network, is running with limited financial support and manpower while it faces the same operational issues and cybersecurity threats as other organizations. Including the existing network facilities and computers for service providing, the increase of mobile devices such as BYOD becomes an issue in terms of misconfiguration and vulnerabilities. The current security systems focus on the backbone network so that the detailed traffic monitoring and data analysis cannot cover the abnormal behavior of all individual endpoints. In general, a misconfigured or intruded computer conducts some abnormal behavior, e.g., sending stray packets, compared to a normal device. Based on this point, we propose a lightweight abnormality detection mechanism by monitoring the stray packets in order to mitigate the above issues. As a result, not only the abnormal behavior can be detected but also maintain the performance of the existing security systems. In this paper, we describe the design and architecture of our proposed Traffic Analyzer', including the implementation and evaluation of our prototype system.

Original languageEnglish
Title of host publicationSIGUCCS 2023 - Proceedings of the 2023 ACM SIGUCCS Annual Conference
PublisherAssociation for Computing Machinery
Pages9-11
Number of pages3
ISBN (Electronic)9781450394116
DOIs
Publication statusPublished - 2023 Mar 20
Event50th ACM SIGUCCS User Services Annual Conference, SIGUCCS 2023 - Chicago, United States
Duration: 2023 Mar 262023 Mar 29

Publication series

NameProceedings ACM SIGUCCS User Services Conference

Conference

Conference50th ACM SIGUCCS User Services Annual Conference, SIGUCCS 2023
Country/TerritoryUnited States
CityChicago
Period23/3/2623/3/29

Keywords

  • abnormal behavior detection
  • lightweight mechanism
  • network security
  • network traffic analysis
  • stray packet monitoring

ASJC Scopus subject areas

  • Computer Science Applications
  • Software
  • Information Systems
  • Education

Fingerprint

Dive into the research topics of 'A Lightweight Abnormality Detection Mechanism by Stray Packets Analysis'. Together they form a unique fingerprint.

Cite this