Back to results

Kennesaw State University

A Framework for Hybrid Intrusion Detection Systems

Abstract

dc:description.abstract

<p>Web application security is a definite threat to the world’s information technology infrastructure. The Open Web Application Security Project (OWASP), generally defines web application security violations as unauthorized or unintentional exposure, disclosure, or loss of personal information. These breaches occur without the company’s knowledge and it often takes a while before the web application attack is revealed to the public, specifically because the security violations are fixed. Due to the need to protect their reputation, organizations have begun researching solutions to these problems. The most widely accepted solution is the use of an Intrusion Detection System (IDS). Such systems currently rely on either signatures of the attack used for the data breach or changes in the behavior patterns of the system to identify an intruder. These systems, either signature-based or anomaly-based, are readily understood by attackers. Issues arise when attacks are not noticed by an existing IDS because the attack does not fit the pre-defined attack signatures the IDS is implemented to discover. Despite current IDSs capabilities, little research has identified a method to detect all potential attacks on a system.</p> <p>This thesis intends to address this problem. A particular emphasis will be placed on detecting advanced attacks, such as those that take place at the application layer. These types of attacks are able to bypass existing IDSs, increase the potential for a web application security breach to occur and not be detected. In particular, the attacks under study are all web application layer attacks. Those included in this thesis are SQL injection, cross-site scripting, directory traversal and remote file inclusion. This work identifies common and existing data breach detection methods as well as the necessary improvements for IDS models. Ultimately, the proposed approach combines an anomaly detection technique measured by cross entropy and a signature-based attack detection framework utilizing genetic algorithm. The proposed hybrid model for data breach detection benefits organizations by increasing security measures and allowing attacks to be identified in less time and more efficiently.</p>

Degree

thesis:*
Name thesis:degree_name
Master of Science in Information Technology (MSIT)
Level thesis:degree_level
Thesis
Discipline thesis:degree_discipline
Information Technology
Year dc:date.available
2016

Author and committee

dc:creator, dc:contributor.*
Author dc:creator
  • Bronte, Robert N
Contributors dc:contributor
  • Hossain Shahriar
  • Hisham Haddad
  • Jack Zheng

Subjects

dc:subject × 8

Identifiers

dc:identifier.*
Repository record dc:identifier
https://digitalcommons.kennesaw.edu/msit_etd/2
OAI identifier oai:identifier
oai:digitalcommons.kennesaw.edu:msit_etd-1002

Chain of custody

source
Harvested from
Kennesaw State University
Base URL
digitalcommons.kennesaw.edu/do/oai/
Last updated
2026-07-24
Source record
OAI-PMH GetRecord
citation

Bronte, Robert N. A Framework for Hybrid Intrusion Detection Systems. Thesis thesis, 2016. https://digitalcommons.kennesaw.edu/msit_etd/2