Anomaly detection using new MIB traffic parameters based on profile

Patthama Sangmee, Nithi Thanon, Nittida Elz · International Conference on Computing Technology and Information Management · 2012

This paper present MIB+, which is an extension of the standard MIB adding parameters to create profiles for intrusion detection. These are based on the Anomaly Detection method to identify the type of intrusion to prevent or find the ways to defeat it. We conducted three experiments to detect a SYN flood attack, DNS flood attack and Null scan. The results are presented in the form of graphs to illustrate trends of network usage, both normal and abnormal.

Read the paper · More papers on PaperTik