{"id":{"repo_id":"aachen","oai_identifier":"oai:publications.rwth-aachen.de:58985"},"canonical_url":"https://search.dev.ndltd.org/etd/aachen/oai:publications.rwth-aachen.de:58985","repository":{"repo_id":"aachen","name":"RWTH Aachen University","base_url":"https://publications.rwth-aachen.de/oai2d"},"display":{"title":"Angriffserkennung in Kommunikationsnetzen","abstract":"Conventional security mechanisms can be overcome by attackers. Therefore, additional systems, so-called intrusion detection systems, are used in communication networks in order to detect such attacks. These systems continuously monitor a network and analyse the recorded events. The analysis can either be done with regard to already known attack signatures (misuse detection), or with regard to deviations from the expected behaviour (anomaly detection). This thesis proposes a new method of anomaly detection. The so-called transaction-based anomaly detection uses a formal definition of the expected behaviour, and is based on the concept of transactions. Transactions originate from the field of databases. In this thesis the transaction properties of atomicity, consistency, isolation and durability (ACID properties) are applied to communication protocols. This enables the classification of possible attacks as well as the development of procedures for the detection of anomalies and the adaptive control of countermeasures.","abstract_html":"Conventional security mechanisms can be overcome by attackers. Therefore, additional systems, so-called intrusion detection systems, are used in communication networks in order to detect such attacks. These systems continuously monitor a network and analyse the recorded events. The analysis can either be done with regard to already known attack signatures (misuse detection), or with regard to deviations from the expected behaviour (anomaly detection). This thesis proposes a new method of anomaly detection. The so-called transaction-based anomaly detection uses a formal definition of the expected behaviour, and is based on the concept of transactions. Transactions originate from the field of databases. In this thesis the transaction properties of atomicity, consistency, isolation and durability (ACID properties) are applied to communication protocols. This enables the classification of possible attacks as well as the development of procedures for the detection of anomalies and the adaptive control of countermeasures.","abstract_has_math":false,"creators":["Büschkes, Roland"],"institution":"Publikationsserver der RWTH Aachen University","degree_name":null,"degree_level":null,"degree_discipline":null,"degree_department":null,"school":null,"contributors":["Spaniol, Otto"],"advisors":[],"committee_chairs":[],"committee_members":[],"year":2001,"date_issued":"2001","date_published":"2001","updated_at":"2026-07-30T19:42:31Z","subjects":["info:eu-repo/classification/ddc/004","Telekommunikationsnetz","Angriff","Erkennung","Transaktion","Aktives Datenbanksystem","Wissensverarbeitung","Informatik","Computerkriminalität","Computersicherheit","Rechnernetz","Monitoring"],"languages":["ger"],"rights":["info:eu-repo/semantics/openAccess"],"rights_urls":[],"identifier_entries":[{"key":"dc:identifier","label":"Identifier","values":["https://publications.rwth-aachen.de/search?p=id:%22RWTH-CONV-120807%22"],"render_values":[{"text":"https://publications.rwth-aachen.de/search?p=id:%22RWTH-CONV-120807%22","href":"https://publications.rwth-aachen.de/search?p=id:%22RWTH-CONV-120807%22","code":true}]}]},"links":{"outbound_url":"https://publications.rwth-aachen.de/record/58985","outbound_label":"Repository record","outbound_source":"dc:identifier"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor","label":"Contributor","values":["Spaniol, Otto"]},{"key":"dc:creator","label":"Author","values":["Büschkes, Roland"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:coverage","label":"Dc Coverage","values":["DE"]},{"key":"dc:date","label":"Dc Date","values":["2001"]},{"key":"dc:publisher","label":"Institution","values":["Publikationsserver der RWTH Aachen University"]},{"key":"dc:relation","label":"Dc Relation","values":["info:eu-repo/semantics/altIdentifier/urn/urn:nbn:de:hbz:82-opus-1882"]},{"key":"dc:type","label":"Dc Type","values":["info:eu-repo/semantics/doctoralThesis","info:eu-repo/semantics/publishedVersion"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["info:eu-repo/classification/ddc/004","Telekommunikationsnetz","Angriff","Erkennung","Transaktion","Aktives Datenbanksystem","Wissensverarbeitung","Informatik","Computerkriminalität","Computersicherheit","Rechnernetz","Monitoring"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:language","label":"Dc Language","values":["ger"]},{"key":"dc:rights","label":"Dc Rights","values":["info:eu-repo/semantics/openAccess"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier","label":"Identifier","values":["https://publications.rwth-aachen.de/record/58985","https://publications.rwth-aachen.de/search?p=id:%22RWTH-CONV-120807%22"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description","label":"Description","values":["Conventional security mechanisms can be overcome by attackers. Therefore, additional systems, so-called intrusion detection systems, are used in communication networks in order to detect such attacks. These systems continuously monitor a network and analyse the recorded events. The analysis can either be done with regard to already known attack signatures (misuse detection), or with regard to deviations from the expected behaviour (anomaly detection). This thesis proposes a new method of anomaly detection. The so-called transaction-based anomaly detection uses a formal definition of the expected behaviour, and is based on the concept of transactions. Transactions originate from the field of databases. In this thesis the transaction properties of atomicity, consistency, isolation and durability (ACID properties) are applied to communication protocols. This enables the classification of possible attacks as well as the development of procedures for the detection of anomalies and the adaptive control of countermeasures."]},{"key":"dc:source","label":"Dc Source","values":["Aachen : Publikationsserver der RWTH Aachen University XII, 213 S. : graph. Darst. (2001). = Aachen, Techn. Hochsch., Diss., 2001"]},{"key":"dc:title","label":"Title","values":["Angriffserkennung in Kommunikationsnetzen"]}]}],"canonical_facts":{"dc:contributor":["Spaniol, Otto"],"dc:coverage":["DE"],"dc:creator":["Büschkes, Roland"],"dc:date":["2001"],"dc:description":["Conventional security mechanisms can be overcome by attackers. Therefore, additional systems, so-called intrusion detection systems, are used in communication networks in order to detect such attacks. These systems continuously monitor a network and analyse the recorded events. The analysis can either be done with regard to already known attack signatures (misuse detection), or with regard to deviations from the expected behaviour (anomaly detection). This thesis proposes a new method of anomaly detection. The so-called transaction-based anomaly detection uses a formal definition of the expected behaviour, and is based on the concept of transactions. Transactions originate from the field of databases. In this thesis the transaction properties of atomicity, consistency, isolation and durability (ACID properties) are applied to communication protocols. This enables the classification of possible attacks as well as the development of procedures for the detection of anomalies and the adaptive control of countermeasures."],"dc:identifier":["https://publications.rwth-aachen.de/record/58985","https://publications.rwth-aachen.de/search?p=id:%22RWTH-CONV-120807%22"],"dc:language":["ger"],"dc:publisher":["Publikationsserver der RWTH Aachen University"],"dc:relation":["info:eu-repo/semantics/altIdentifier/urn/urn:nbn:de:hbz:82-opus-1882"],"dc:rights":["info:eu-repo/semantics/openAccess"],"dc:source":["Aachen : Publikationsserver der RWTH Aachen University XII, 213 S. : graph. Darst. (2001). = Aachen, Techn. Hochsch., Diss., 2001"],"dc:subject":["info:eu-repo/classification/ddc/004","Telekommunikationsnetz","Angriff","Erkennung","Transaktion","Aktives Datenbanksystem","Wissensverarbeitung","Informatik","Computerkriminalität","Computersicherheit","Rechnernetz","Monitoring"],"dc:title":["Angriffserkennung in Kommunikationsnetzen"],"dc:type":["info:eu-repo/semantics/doctoralThesis","info:eu-repo/semantics/publishedVersion"]},"updated_at":"2026-07-30T19:42:31Z"}