Statistical Behavior of Packet Counts for Network Intrusion Detection

Rania A. Ghazy, El‐Sayed M. El‐Rabaie, Moawad Ibrahim Dessouky, Nawal A. El-Feshawy, Fathi E. Abd El‐Samie · CiiT international journal of networking and communication engineering · 2014

Intrusions and attacks have become a very serious 1 problem in network world. This paper presents a statistical 2 characterization of packet counts that can be used for network 3 intrusion detection. The main idea is based on detecting any suspicious 4 behavior in computer networks depending on the comparison between 5 the correlation results of control and data planes in the presence and 6 absence of attacks using histogram analysis. Signal processing tools 7 such as median filtering, moving average filtering, and local variance 8 estimators are exploited to help in developing network anomaly 9 detection approaches. Therefore, detecting dissimilarity can indicate 10 an abnormal behavior. 11 12 13 Detection Systems (NIDS). 14

Read the paper · More papers on PaperTik