TSUBAME (International network traffic monitoring project)
-
TSUBAME is a project for monitoring and visualizing Internet traffic, and has been
implemented since 2007. The project was developed under the framework of the Asia
Pacific Computer Emergency Response Team (APCERT), which is a community of
Computer Security Incident Response Teams (CSIRT*) in the Asia Pacific region. The
project was initiated and is led by JPCERT/CC.
- This project installs monitoring sensors in the national CSIRTs of the Asia Pacific region
(as of September 2013, sensors have been installed in 23 teams in 20 economic regions),
and visualizes the monitoring results in the region. The project is aimed at strengthening
collaboration among CSIRTs (cooperation in responding to cross-border security incidents,
and sharing threat information and analysis capabilities) through the process of gathering
and visualizing malicious Internet activities detected by each sensor, sharing this
information among all members, and responding to them together.
Visualization of packet
transmissions captured
by sensors
Framework for sharing
traffic monitoring data in
the Asia Pacific region
Country A
Country B
Data sharing on
analytical information,
including trends of cyber
attacks
Country C
Country E
Country D
(Reference) Overview of the project
-
This project enables incident responses and other cooperative activities at the operational level by
sharing the data collaboratively monitored by CSIRTs in each country/region and creating an analysis
platform for situation assessment and swift responses.
-
Participating members of the project share the results of the analyzed data. These data are used for
incident responses through such measures as issuance of analysis reports. An annual TSUBAME
workshop is also held to share analysis methods, to improve analysis capabilities, and to enhance
incident response skills.
-
Participating members analyze and exchange information on trends of worm infection and scanning
activities to search weak points. Members also carry out joint research on such themes as methods for
threat visualization in order to efficiently understand the trends of worm infection and scanning activities
to search for weak points.
* Abbreviation of Computer Security Incident Response Team. It serves as a point of contact when cyber attacks occur
and is also an expert organization that responds to these cyber attacks.
15