{"id":{"repo_id":"iastate","oai_identifier":"oai:dr.lib.iastate.edu:20.500.12876/26563"},"canonical_url":"https://search.dev.ndltd.org/etd/iastate/oai:dr.lib.iastate.edu:20.500.12876/26563","repository":{"repo_id":"iastate","name":"Iowa State University","base_url":"https://dr.lib.iastate.edu/server/oai/request"},"display":{"title":"Detecting exploit patterns from network packet streams","abstract":"<p>Network-based Intrusion Detection Systems (NIDS), e.g., Snort, Bro or NSM, try to detect malicious network activity such as Denial of Service (DoS) attacks and port scans by monitoring network traffic. Research from network traffic measurement has identified various patterns that exploits on today's Internet typically exhibit. However, there has not been any significant attempt, so far, to design algorithms with provable guarantees for detecting exploit patterns from network traffic packets. In this work, we develop and apply data streaming algorithms to detect exploit patterns from network packet streams.</p> <p>In network intrusion detection, it is necessary to analyze large volumes of data in an online fashion. Our work addresses scalable analysis of data under the following situations. (1) Attack traffic can be stealthy in nature, which means detecting a few covert attackers might call for checking traffic logs of days or even months, (2) Traffic is multidimensional and correlations between multiple dimensions maybe important, and (3) Sometimes traffic from multiple sources may need to be analyzed in a combined manner. Our algorithms offer provable bounds on resource consumption and approximation error. Our theoretical results are supported by experiments over real network traces and synthetic datasets.</p>","abstract_html":"&lt;p&gt;Network-based Intrusion Detection Systems (NIDS), e.g., Snort, Bro or NSM, try to detect malicious network activity such as Denial of Service (DoS) attacks and port scans by monitoring network traffic. Research from network traffic measurement has identified various patterns that exploits on today&#x27;s Internet typically exhibit. However, there has not been any significant attempt, so far, to design algorithms with provable guarantees for detecting exploit patterns from network traffic packets. In this work, we develop and apply data streaming algorithms to detect exploit patterns from network packet streams.&lt;/p&gt; &lt;p&gt;In network intrusion detection, it is necessary to analyze large volumes of data in an online fashion. Our work addresses scalable analysis of data under the following situations. (1) Attack traffic can be stealthy in nature, which means detecting a few covert attackers might call for checking traffic logs of days or even months, (2) Traffic is multidimensional and correlations between multiple dimensions maybe important, and (3) Sometimes traffic from multiple sources may need to be analyzed in a combined manner. Our algorithms offer provable bounds on resource consumption and approximation error. Our theoretical results are supported by experiments over real network traces and synthetic datasets.&lt;/p&gt;","abstract_has_math":false,"creators":["Lahiri, Bibudh"],"institution":null,"degree_name":"Doctor of Philosophy","degree_level":"dissertation","degree_discipline":null,"degree_department":"Department of Electrical and Computer Engineering","school":null,"contributors":[],"advisors":["Srikanta Tirthapura","Yong Guan"],"committee_chairs":[],"committee_members":[],"year":2012,"date_issued":"2012-01-01","date_published":"2012-01-01","updated_at":"2026-07-24T02:39:53Z","subjects":[],"languages":["en"],"rights":[],"rights_urls":[],"identifier_entries":[{"key":"dc:identifier.doi","label":"DOI","values":["https://doi.org/10.31274/etd-180810-2263"],"render_values":[{"text":"https://doi.org/10.31274/etd-180810-2263","href":"https://doi.org/10.31274/etd-180810-2263","code":true}]},{"key":"dc:identifier","label":"Identifier","values":["archive/lib.dr.iastate.edu/etd/12374/"],"render_values":[{"text":"archive/lib.dr.iastate.edu/etd/12374/","href":null,"code":true}]}]},"links":{"outbound_url":"https://dr.lib.iastate.edu/handle/20.500.12876/26563","outbound_label":"Repository record","outbound_source":"dc:identifier.uri"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor.advisor","label":"Advisor","values":["Srikanta Tirthapura","Yong Guan"]},{"key":"dc:contributor.department","label":"Department","values":["Department of Electrical and Computer Engineering"]},{"key":"dc:creator","label":"Author","values":["Lahiri, Bibudh"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date","label":"Dc Date","values":["2018-08-11T22:06:40.000"]},{"key":"dc:date.accessioned","label":"Dc Date Accessioned","values":["2020-06-30T02:42:14Z"]},{"key":"dc:date.available","label":"Dc Date Available","values":["2020-06-30T02:42:14Z"]},{"key":"dc:date.issued","label":"Date","values":["2012-01-01"]},{"key":"dc:type","label":"Dc Type","values":["dissertation"]},{"key":"thesis:degree_level","label":"Degree Level","values":["dissertation"]},{"key":"thesis:degree_name","label":"Degree Name","values":["Doctor of Philosophy"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:language.iso","label":"Language (ISO)","values":["en"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier","label":"Identifier","values":["archive/lib.dr.iastate.edu/etd/12374/"]},{"key":"dc:identifier.doi","label":"DOI","values":["https://doi.org/10.31274/etd-180810-2263"]},{"key":"dc:identifier.uri","label":"Identifier URI","values":["https://dr.lib.iastate.edu/handle/20.500.12876/26563"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description.abstract","label":"Abstract","values":["<p>Network-based Intrusion Detection Systems (NIDS), e.g., Snort, Bro or NSM, try to detect malicious network activity such as Denial of Service (DoS) attacks and port scans by monitoring network traffic. Research from network traffic measurement has identified various patterns that exploits on today's Internet typically exhibit. However, there has not been any significant attempt, so far, to design algorithms with provable guarantees for detecting exploit patterns from network traffic packets. In this work, we develop and apply data streaming algorithms to detect exploit patterns from network packet streams.</p> <p>In network intrusion detection, it is necessary to analyze large volumes of data in an online fashion. Our work addresses scalable analysis of data under the following situations. (1) Attack traffic can be stealthy in nature, which means detecting a few covert attackers might call for checking traffic logs of days or even months, (2) Traffic is multidimensional and correlations between multiple dimensions maybe important, and (3) Sometimes traffic from multiple sources may need to be analyzed in a combined manner. Our algorithms offer provable bounds on resource consumption and approximation error. Our theoretical results are supported by experiments over real network traces and synthetic datasets.</p>"]},{"key":"dc:format.mimetype","label":"Dc Format Mimetype","values":["application/pdf"]},{"key":"dc:title","label":"Title","values":["Detecting exploit patterns from network packet streams"]}]}],"canonical_facts":{"dc:contributor.advisor":["Srikanta Tirthapura","Yong Guan"],"dc:contributor.department":["Department of Electrical and Computer Engineering"],"dc:creator":["Lahiri, Bibudh"],"dc:date":["2018-08-11T22:06:40.000"],"dc:date.accessioned":["2020-06-30T02:42:14Z"],"dc:date.available":["2020-06-30T02:42:14Z"],"dc:date.issued":["2012-01-01"],"dc:description.abstract":["<p>Network-based Intrusion Detection Systems (NIDS), e.g., Snort, Bro or NSM, try to detect malicious network activity such as Denial of Service (DoS) attacks and port scans by monitoring network traffic. Research from network traffic measurement has identified various patterns that exploits on today's Internet typically exhibit. However, there has not been any significant attempt, so far, to design algorithms with provable guarantees for detecting exploit patterns from network traffic packets. In this work, we develop and apply data streaming algorithms to detect exploit patterns from network packet streams.</p> <p>In network intrusion detection, it is necessary to analyze large volumes of data in an online fashion. Our work addresses scalable analysis of data under the following situations. (1) Attack traffic can be stealthy in nature, which means detecting a few covert attackers might call for checking traffic logs of days or even months, (2) Traffic is multidimensional and correlations between multiple dimensions maybe important, and (3) Sometimes traffic from multiple sources may need to be analyzed in a combined manner. Our algorithms offer provable bounds on resource consumption and approximation error. Our theoretical results are supported by experiments over real network traces and synthetic datasets.</p>"],"dc:format.mimetype":["application/pdf"],"dc:identifier":["archive/lib.dr.iastate.edu/etd/12374/"],"dc:identifier.doi":["https://doi.org/10.31274/etd-180810-2263"],"dc:identifier.uri":["https://dr.lib.iastate.edu/handle/20.500.12876/26563"],"dc:language.iso":["en"],"dc:title":["Detecting exploit patterns from network packet streams"],"dc:type":["dissertation"],"thesis:degree_level":["dissertation"],"thesis:degree_name":["Doctor of Philosophy"]},"updated_at":"2026-07-24T02:39:53Z"}