Skip to Main Content
 

Global Search Box

 
 
 
 

ETD Abstract Container

Abstract Header

Analysis of Time-Based Approach for Detecting Anomalous Network Traffic

Khasgiwala, Jitesh

Abstract Details

2005, Master of Science (MS), Ohio University, Computer Science (Engineering).

The Multiple Self-Organizing map based Intrusion Detection System (MSIDS) is a recent approach for an anomaly-based IDS developed under the Integrated Network-Based Ohio University Network Detective Service (INBOUNDS). It enhanced the previous approach by introducing the time-based behavior of normal network connections. It analyzed the time-based behavior using a pattern and demonstrated the better characterization of network behavior. This thesis provides a detail analysis of this work by investigating various options for time-based approach. The analysis of a heuristic approach for automatic generation of patterns, and generation of two specific patterns is performed. The detailed false positive analysis for these patterns and MSIDS pattern is then accomplished using four training data sets. A methodology is devised for tuning the pattern generation algorithm that eliminates the false positives for the training data sets. The inherent false positive rate resulted from the threshold adopted from previous work is reduced by finding the new threshold value.

Shawn Ostermann (Advisor)
111 p.

Recommended Citations

Citations

  • Khasgiwala, J. (2005). Analysis of Time-Based Approach for Detecting Anomalous Network Traffic [Master's thesis, Ohio University]. OhioLINK Electronic Theses and Dissertations Center. http://rave.ohiolink.edu/etdc/view?acc_num=ohiou1113583042

    APA Style (7th edition)

  • Khasgiwala, Jitesh. Analysis of Time-Based Approach for Detecting Anomalous Network Traffic. 2005. Ohio University, Master's thesis. OhioLINK Electronic Theses and Dissertations Center, http://rave.ohiolink.edu/etdc/view?acc_num=ohiou1113583042.

    MLA Style (8th edition)

  • Khasgiwala, Jitesh. "Analysis of Time-Based Approach for Detecting Anomalous Network Traffic." Master's thesis, Ohio University, 2005. http://rave.ohiolink.edu/etdc/view?acc_num=ohiou1113583042

    Chicago Manual of Style (17th edition)