{"id":{"repo_id":"mit","oai_identifier":"oai:dspace.mit.edu:1721.1/41634"},"canonical_url":"https://search.dev.ndltd.org/etd/mit/oai:dspace.mit.edu:1721.1/41634","repository":{"repo_id":"mit","name":"MIT","base_url":"https://dspace.mit.edu/oai/request"},"display":{"title":"Modeling how users interact with Windows Outlook to crate realistic email traffic","abstract":"The ever-present and increasing threat of abuse requires a systematic approach to information assurance to protect the security of systems and data. The Lincoln Adaptable Real-time Information Assurance Testbed (LARIAT) was developed to simplify and address problems that surfaced from DARPA evaluations on intrusion detection systems (IDS) development. LARIAT emulates the network traffic produced from one or more organizations connected to the internet. This thesis work focuses on developing the Outlook email model in WinNTGen, which simulates native Windows traffic in LARIAT. To accurately characterize email network traffic, data from seven real users is collected using an Outlook add-in built on the Microsoft .NET Framework for analysis to produce a more realistic usage behavior model. The analysis determined that users behave differently. Therefore, a state machine of the 20 prevailing user actions, and the 76 prevailing transitions was created for each user, to model each user separately.","abstract_html":"The ever-present and increasing threat of abuse requires a systematic approach to information assurance to protect the security of systems and data. The Lincoln Adaptable Real-time Information Assurance Testbed (LARIAT) was developed to simplify and address problems that surfaced from DARPA evaluations on intrusion detection systems (IDS) development. LARIAT emulates the network traffic produced from one or more organizations connected to the internet. This thesis work focuses on developing the Outlook email model in WinNTGen, which simulates native Windows traffic in LARIAT. To accurately characterize email network traffic, data from seven real users is collected using an Outlook add-in built on the Microsoft .NET Framework for analysis to produce a more realistic usage behavior model. The analysis determined that users behave differently. Therefore, a state machine of the 20 prevailing user actions, and the 76 prevailing transitions was created for each user, to model each user separately.","abstract_has_math":false,"creators":["Hsu, Lisa, M. Eng. Massachusetts Institute of Technology"],"institution":"Massachusetts Institute of Technology","degree_name":null,"degree_level":null,"degree_discipline":null,"degree_department":"Massachusetts Institute of Technology. Dept. of Electrical Engineering and Computer Science.","school":null,"contributors":[],"advisors":["Richard Lippmann."],"committee_chairs":[],"committee_members":[],"year":2007,"date_issued":"2007","date_published":"2007","updated_at":"2026-07-22T22:21:59Z","subjects":["Electrical Engineering and Computer Science."],"languages":["eng"],"rights":["M.I.T. theses are protected by copyright. They may be viewed from this source for any purpose, but reproduction or distribution in any format is prohibited without written permission. See provided URL for inquiries about permission."],"rights_urls":["http://dspace.mit.edu/handle/1721.1/7582"],"identifier_entries":[]},"links":{"outbound_url":"http://hdl.handle.net/1721.1/41634","outbound_label":"Handle","outbound_source":"dc:identifier.uri"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor.advisor","label":"Advisor","values":["Richard Lippmann."]},{"key":"dc:contributor.department","label":"Department","values":["Massachusetts Institute of Technology. Dept. of Electrical Engineering and Computer Science."]},{"key":"dc:contributor.other","label":"Dc Contributor Other","values":["Massachusetts Institute of Technology. Dept. of Electrical Engineering and Computer Science."]},{"key":"dc:creator","label":"Author","values":["Hsu, Lisa, M. Eng. Massachusetts Institute of Technology"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date.accessioned","label":"Dc Date Accessioned","values":["2008-05-19T16:03:27Z"]},{"key":"dc:date.available","label":"Dc Date Available","values":["2008-05-19T16:03:27Z"]},{"key":"dc:date.issued","label":"Date","values":["2007"]},{"key":"dc:publisher","label":"Institution","values":["Massachusetts Institute of Technology"]},{"key":"dc:type","label":"Dc Type","values":["Thesis"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["Electrical Engineering and Computer Science."]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:language.iso","label":"Language (ISO)","values":["eng"]},{"key":"dc:rights","label":"Dc Rights","values":["M.I.T. theses are protected by copyright. They may be viewed from this source for any purpose, but reproduction or distribution in any format is prohibited without written permission. See provided URL for inquiries about permission."]},{"key":"dc:rights.uri","label":"Rights URI","values":["http://dspace.mit.edu/handle/1721.1/7582"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier.uri","label":"Identifier URI","values":["http://hdl.handle.net/1721.1/41634"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description","label":"Description","values":["Thesis (M. Eng.)--Massachusetts Institute of Technology, Dept. of Electrical Engineering and Computer Science, June 2007.","Includes bibliographical references (p. 119-120)."]},{"key":"dc:description.abstract","label":"Abstract","values":["The ever-present and increasing threat of abuse requires a systematic approach to information assurance to protect the security of systems and data. The Lincoln Adaptable Real-time Information Assurance Testbed (LARIAT) was developed to simplify and address problems that surfaced from DARPA evaluations on intrusion detection systems (IDS) development. LARIAT emulates the network traffic produced from one or more organizations connected to the internet. This thesis work focuses on developing the Outlook email model in WinNTGen, which simulates native Windows traffic in LARIAT. To accurately characterize email network traffic, data from seven real users is collected using an Outlook add-in built on the Microsoft .NET Framework for analysis to produce a more realistic usage behavior model. The analysis determined that users behave differently. Therefore, a state machine of the 20 prevailing user actions, and the 76 prevailing transitions was created for each user, to model each user separately."]},{"key":"dc:description.degree","label":"Dc Description Degree","values":["M.Eng."]},{"key":"dc:title","label":"Title","values":["Modeling how users interact with Windows Outlook to crate realistic email traffic"]}]}],"canonical_facts":{"dc:contributor.advisor":["Richard Lippmann."],"dc:contributor.department":["Massachusetts Institute of Technology. Dept. of Electrical Engineering and Computer Science."],"dc:contributor.other":["Massachusetts Institute of Technology. Dept. of Electrical Engineering and Computer Science."],"dc:creator":["Hsu, Lisa, M. Eng. Massachusetts Institute of Technology"],"dc:date.accessioned":["2008-05-19T16:03:27Z"],"dc:date.available":["2008-05-19T16:03:27Z"],"dc:date.issued":["2007"],"dc:description":["Thesis (M. Eng.)--Massachusetts Institute of Technology, Dept. of Electrical Engineering and Computer Science, June 2007.","Includes bibliographical references (p. 119-120)."],"dc:description.abstract":["The ever-present and increasing threat of abuse requires a systematic approach to information assurance to protect the security of systems and data. The Lincoln Adaptable Real-time Information Assurance Testbed (LARIAT) was developed to simplify and address problems that surfaced from DARPA evaluations on intrusion detection systems (IDS) development. LARIAT emulates the network traffic produced from one or more organizations connected to the internet. This thesis work focuses on developing the Outlook email model in WinNTGen, which simulates native Windows traffic in LARIAT. To accurately characterize email network traffic, data from seven real users is collected using an Outlook add-in built on the Microsoft .NET Framework for analysis to produce a more realistic usage behavior model. The analysis determined that users behave differently. Therefore, a state machine of the 20 prevailing user actions, and the 76 prevailing transitions was created for each user, to model each user separately."],"dc:description.degree":["M.Eng."],"dc:identifier.uri":["http://hdl.handle.net/1721.1/41634"],"dc:language.iso":["eng"],"dc:publisher":["Massachusetts Institute of Technology"],"dc:rights":["M.I.T. theses are protected by copyright. They may be viewed from this source for any purpose, but reproduction or distribution in any format is prohibited without written permission. See provided URL for inquiries about permission."],"dc:rights.uri":["http://dspace.mit.edu/handle/1721.1/7582"],"dc:subject":["Electrical Engineering and Computer Science."],"dc:title":["Modeling how users interact with Windows Outlook to crate realistic email traffic"],"dc:type":["Thesis"]},"updated_at":"2026-07-22T22:21:59Z"}