Anomaly detection using new MIB traffic parameters based on profile
Patthama Sangmee, Nithi Thanon, Nittida Elz · International Conference on Computing Technology and Information Management · 2012
This paper present MIB+, which is an extension of the standard MIB adding parameters to create profiles for intrusion detection. These are based on the Anomaly Detection method to identify the type of intrusion to prevent or find the ways to defeat it. We conducted three experiments to detect a SYN flood attack, DNS flood attack and Null scan. The results are presented in the form of graphs to illustrate trends of network usage, both normal and abnormal.