Network Intrusion and Failure Detection System with Statistical Analyses of Packet Headers
K. Goto, K. Kojima · 2006
In this research, practical application for quasi-realtime intrusion and network failure detection was designed and implemented. IP packet headers are counted at the monitoring point and summarized in every 5 minutes. Then four kind of statistical analyses are applied to the 5-minute summaries to find a sudden increase/decrease. As the result, the developed application works fine with a standard desktop PC. Warnings were reported in at most 1 minute after every 5-minute summary. In addition to the warning report, Web interfaces were implemented to help the administrator to trace the cause of a warning.