Anomaly-based online intrusion detection system as a sensor for cyber security situational awareness system
Almost all the organisations and even individuals rely on complex structures of
data networks and networked computer systems. That complex data ensemble,
the cyber domain, provides great opportunities, but at the same time it offers
many possible attack vectors that can be abused for cyber vandalism, cyber crime,
cyber espionage or cyber terrorism. Those threats produce requirements for cyber security situational awareness and intrusion detection capability. This dissertation concentrates on research and development of anomaly-based network
intrusion detection system as a sensor for a situational awareness system. In this
dissertation, several models of intrusion detection systems are developed using
clustering-based data-mining algorithms for creating a model of normal user behaviour and finding similarities and dissimilarities compared to that model. That
information can be used as a sensor feed in a situational awareness system in cyber security. A model of cyber security situational awareness system with multisensor fusion capability is presented in this thesis. Also a model for exchanging
the information of cyber security situational awareness is generated. The constructed intrusion detection system schemes are tested with different scenarios
even in online mode with real user data.
...
Publisher
University of JyväskyläISBN
978-951-39-6832-8ISSN Search the Publication Forum
1456-5390Keywords
Metadata
Show full item recordCollections
- Väitöskirjat [3435]
Related items
Showing items with similar title or keywords.
-
Intrusion detection applications using knowledge discovery and data mining
Juvonen, Antti (University of Jyväskylä, 2014) -
UInDeSI4.0 : An efficient Unsupervised Intrusion Detection System for network traffic flow in Industry 4.0 ecosystem
Shukla, Amit, K.; Srivastav, Shubham; Kumar, Sandeep; Muhuri, Pranab, K. (Elsevier BV, 2023)In an Industry 4.0 ecosystem, all the essential components are digitally interconnected, and automation is integrated for higher productivity. However, it invites the risk of increasing cyber-attacks amid the current cyber ... -
An Efficient Network Log Anomaly Detection System using Random Projection Dimensionality Reduction
Juvonen, Antti; Hämäläinen, Timo (IEEE, 2014)Network traffic is increasing all the time and network services are becoming more complex and vulnerable. To protect these networks, intrusion detection systems are used. Signature-based intrusion detection cannot find ... -
Dimensionality reduction framework for detecting anomalies from network logs
Sipola, Tuomo; Juvonen, Antti; Lehtonen, Joel (CRL Publishing, 2012)Dynamic web services are vulnerable to multitude of intrusions that could be previously unknown. Server logs contain vast amounts of information about network traffic, and finding attacks from these logs improves the ... -
Anomaly detection from network logs using diffusion maps
Sipola, Tuomo; Juvonen, Antti; Lehtonen, Joel (Springer, 2011)The goal of this study is to detect anomalous queries from network logs using a dimensionality reduction framework. The fequencies of 2-grams in queries are extracted to a feature matrix. Dimensionality reduction is done ...