Back to results

NJIT

Network anomaly detection using management information base (MIB) network traffic variables

Abstract

dc:description.abstract

In this dissertation, a hierarchical, multi-tier, multiple-observation-window, network anomaly detection system (NADS) is introduced, namely, the MIB Anomaly Detection (MAD) system, which is capable of detecting and diagnosing network anomalies (including network faults and Denial of Service computer network attacks) proactively and adaptively. The MAD system utilizes statistical models and neural network classifier to detect network anomalies through monitoring the subtle changes of network traffic patterns. The process of measuring network traffic pattern is achieved by monitoring the Management Information Base (Mifi) II variables, supplied by the Simple Network Management Protocol (SNMP) LI. The MAD system then converted each monitored Mifi variable values, collected during each observation window, into a Probability Density Function (PDF), processed them statistically, combined intelligently the result for each individual variable and derived the final decision. The MAD system has a distributed, hierarchical, multi-tier architecture, based on which it could provide the health status of each network individual element. The inter-tier communication requires low network bandwidth, thus, making it possibly utilization on capacity challenged wireless as well as wired networks. Efficiently and accurately modeling network traffic behavior is essential for building NADS. In this work, a novel approach to statistically model network traffic measurements with high variability is introduced, that is, dividing the network traffic measurements into three different frequency segments and modeling the data in each frequency segment separately. Also in this dissertation, a new network traffic statistical model, i.e., the one-dimension hyperbolic distribution, is introduced.

Degree

thesis:*
Name thesis:degree_name
Doctor of Philosophy in Electrical Engineering - (Ph.D.)
Discipline thesis:degree_discipline
Electrical and Computer Engineering
Year
2004

Author and committee

dc:creator, dc:contributor.*
Author dc:creator
  • Li, Jun
Contributors dc:contributor
  • Constantine N. Manikopoulos
  • Ali N. Akansu
  • Edwin Hou

Subjects

dc:subject × 5

Identifiers

dc:identifier.*
Repository record dc:identifier
https://digitalcommons.njit.edu/dissertations/656
OAI identifier oai:identifier
oai:digitalcommons.njit.edu:dissertations-1711

Chain of custody

source
Harvested from
NJIT
Base URL
digitalcommons.njit.edu/do/oai/
Last updated
2026-07-24
Source record
OAI-PMH GetRecord
citation

Li, Jun. Network anomaly detection using management information base (MIB) network traffic variables. 2004. https://digitalcommons.njit.edu/dissertations/656