Back to results

Iowa State University

Detecting exploit patterns from network packet streams

Abstract

dc:description.abstract

<p>Network-based Intrusion Detection Systems (NIDS), e.g., Snort, Bro or NSM, try to detect malicious network activity such as Denial of Service (DoS) attacks and port scans by monitoring network traffic. Research from network traffic measurement has identified various patterns that exploits on today's Internet typically exhibit. However, there has not been any significant attempt, so far, to design algorithms with provable guarantees for detecting exploit patterns from network traffic packets. In this work, we develop and apply data streaming algorithms to detect exploit patterns from network packet streams.</p> <p>In network intrusion detection, it is necessary to analyze large volumes of data in an online fashion. Our work addresses scalable analysis of data under the following situations. (1) Attack traffic can be stealthy in nature, which means detecting a few covert attackers might call for checking traffic logs of days or even months, (2) Traffic is multidimensional and correlations between multiple dimensions maybe important, and (3) Sometimes traffic from multiple sources may need to be analyzed in a combined manner. Our algorithms offer provable bounds on resource consumption and approximation error. Our theoretical results are supported by experiments over real network traces and synthetic datasets.</p>

Degree

thesis:*
Name thesis:degree_name
Doctor of Philosophy
Level thesis:degree_level
dissertation
Department dc:contributor.department
Department of Electrical and Computer Engineering
Year dc:date.issued
2012

Author and committee

dc:creator, dc:contributor.*
Author dc:creator
  • Lahiri, Bibudh
Advisors dc:contributor.advisor
  • Srikanta Tirthapura
  • Yong Guan

Rights

Language dc:language.iso
en

Identifiers

dc:identifier.*
Identifier
archive/lib.dr.iastate.edu/etd/12374/
OAI identifier oai:identifier
oai:dr.lib.iastate.edu:20.500.12876/26563

Chain of custody

source
Harvested from
Iowa State University
Base URL
dr.lib.iastate.edu/server/oai/request
Last updated
2026-07-24
Source record
OAI-PMH GetRecord
related terms
citation

Lahiri, Bibudh. Detecting exploit patterns from network packet streams. dissertation thesis, 2012. https://dr.lib.iastate.edu/handle/20.500.12876/26563