Network Intrusion Monitoring System Wavelet Analysis Traffic
Bogdan Petrik, Valeriy I. Dubrovin, Hanna Nelasa, Yulia Tverdokhlib · 2020
The modern development of the field of cybersecurity shows the need for the development of new and modification of existing algorithms for traffic analysis in network systems. A detailed analysis of the simulated traffic using large data processing technologies is presented. The advantage of this technology is that it allows you to show the features of the local structure of a complex signal and to reveal its various properties that are invisible in real time. In the field of wavelet transform, additional information is extracted using the representation in the time-frequency image of a signal that is not available in its original form. The expediency of creating a hybrid network traffic monitoring system based on wavelet analysis has been substantiated. The use of wavelet bases for solving this problem has a leading position. The choice of the optimal wavelet basis will increase the probability of detecting attacks. The combination of several wavelet bases can give a better result in detecting intrusions into computer networks compared to monitoring based on a single wavelet base. When considering different methods of wavelet analysis to solve this problem, not identical examples of simulating attacked network traffic are used. Simulated traffic consisting of a real trace of an attack can show the full effectiveness of this method. Integrated and hybrid experimental research systems will not only save time difference for developing a detection system in Brandmauer itself, but also gain the effectiveness of multiple detection methods.