Discovering traffic anomolies and attacks using flow-based analysis.

Nitu Barua · 2013

With the increasing number of computer systems and networks are connected to the Internet, security becomes a critical issue. Broadband Internet connectivity and an exponential growth in the worldwide IT infrastructure, individuals and or- ganizations now rely heavily on the Internet for their communication and business needs. While such readily-available network connectivity facilitates operational eff- ciency and networking, systems connected to the Internet are inherently vulnerable to network attacks. Network anomalies can varies from network outages and flash crowds, to malicious attacks such as denial of service attacks, distributed denial of service attacks and so on There is considerable interest in using entropy-based analysis and histogram based analysis of trac feature distributions for anomaly detection. Entropy-based metrics are appealing since they provide more ne-grained insights into trac struc- ture than traditional trac volume analysis. The aim of my thesis is to analyzed collected NetFlow data from the backbone network of Uninett, and detect anomalies and identied dierent types of anomalies. Then address the conclusion and future work.

Read the paper · More papers on PaperTik