{"id":{"repo_id":"ucf","oai_identifier":"oai:stars.library.ucf.edu:etd-1538"},"canonical_url":"https://search.dev.ndltd.org/etd/ucf/oai:stars.library.ucf.edu:etd-1538","repository":{"repo_id":"ucf","name":"Central Florida","base_url":"https://stars.library.ucf.edu/do/oai/"},"display":{"title":"Session-based Intrusion Detection System To Map Anomalous Network Traffic","abstract":"Computer crime is a large problem (CSI, 2004; Kabay, 2001a; Kabay, 2001b). Security managers have a variety of tools at their disposal -- firewalls, Intrusion Detection Systems (IDSs), encryption, authentication, and other hardware and software solutions to combat computer crime. Many IDS variants exist which allow security managers and engineers to identify attack network packets primarily through the use of signature detection; i.e., the IDS recognizes attack packets due to their well-known \"fingerprints\" or signatures as those packets cross the network's gateway threshold. On the other hand, anomaly-based ID systems determine what is normal traffic within a network and reports abnormal traffic behavior. This paper will describe a methodology towards developing a more-robust Intrusion Detection System through the use of data-mining techniques and anomaly detection. These data-mining techniques will dynamically model what a normal network should look like and reduce the false positive and false negative alarm rates in the process. We will use classification-tree techniques to accurately predict probable attack sessions. Overall, our goal is to model network traffic into network sessions and identify those network sessions that have a high-probability of being an attack and can be labeled as a \"suspect session.\" Subsequently, we will use these techniques inclusive of signature detection methods, as they will be used in concert with known signatures and patterns in order to present a better model for detection and protection of networks and systems.","abstract_html":"Computer crime is a large problem (CSI, 2004; Kabay, 2001a; Kabay, 2001b). Security managers have a variety of tools at their disposal -- firewalls, Intrusion Detection Systems (IDSs), encryption, authentication, and other hardware and software solutions to combat computer crime. Many IDS variants exist which allow security managers and engineers to identify attack network packets primarily through the use of signature detection; i.e., the IDS recognizes attack packets due to their well-known &quot;fingerprints&quot; or signatures as those packets cross the network&#x27;s gateway threshold. On the other hand, anomaly-based ID systems determine what is normal traffic within a network and reports abnormal traffic behavior. This paper will describe a methodology towards developing a more-robust Intrusion Detection System through the use of data-mining techniques and anomaly detection. These data-mining techniques will dynamically model what a normal network should look like and reduce the false positive and false negative alarm rates in the process. We will use classification-tree techniques to accurately predict probable attack sessions. Overall, our goal is to model network traffic into network sessions and identify those network sessions that have a high-probability of being an attack and can be labeled as a &quot;suspect session.&quot; Subsequently, we will use these techniques inclusive of signature detection methods, as they will be used in concert with known signatures and patterns in order to present a better model for detection and protection of networks and systems.","abstract_has_math":false,"creators":["Caulkins, Bruce"],"institution":null,"degree_name":null,"degree_level":null,"degree_discipline":null,"degree_department":null,"school":null,"contributors":["Wang, Morgan"],"advisors":[],"committee_chairs":[],"committee_members":[],"year":2005,"date_issued":"2005-01-01T08:00:00Z","date_published":"2005-01-01T08:00:00Z","updated_at":"2026-07-24T05:08:59Z","subjects":["Data Mining","Intrusion Detection Systems","Anomaly Detection","Network Modeling","Categorical Data Analysis"],"languages":["English"],"rights":[],"rights_urls":[],"identifier_entries":[{"key":"dc:identifier","label":"Identifier","values":["CFE0000906"],"render_values":[{"text":"CFE0000906","href":null,"code":true}]}]},"links":{"outbound_url":"https://stars.library.ucf.edu/etd/539","outbound_label":"Repository record","outbound_source":"dc:identifier.uri"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor","label":"Contributor","values":["Wang, Morgan"]},{"key":"dc:creator","label":"Author","values":["Caulkins, Bruce"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:type","label":"Dc Type","values":["Doctoral Dissertation (Open Access)"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["Data Mining","Intrusion Detection Systems","Anomaly Detection","Network Modeling","Categorical Data Analysis"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:language","label":"Dc Language","values":["English"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier","label":"Identifier","values":["CFE0000906"]},{"key":"dc:identifier.uri","label":"Identifier URI","values":["https://stars.library.ucf.edu/etd/539"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description","label":"Description","values":["<p>If this is your thesis or dissertation, and want to learn how to access it or for more information about readership statistics, contact us at <a href=\"mailto:STARS@ucf.edu\">STARS@ucf.edu</a></p>","Doctor of Philosophy (Ph.D.)","College of Arts and Sciences","Modeling and Simulation"]},{"key":"dc:description.abstract","label":"Abstract","values":["Computer crime is a large problem (CSI, 2004; Kabay, 2001a; Kabay, 2001b). Security managers have a variety of tools at their disposal -- firewalls, Intrusion Detection Systems (IDSs), encryption, authentication, and other hardware and software solutions to combat computer crime. Many IDS variants exist which allow security managers and engineers to identify attack network packets primarily through the use of signature detection; i.e., the IDS recognizes attack packets due to their well-known \"fingerprints\" or signatures as those packets cross the network's gateway threshold. On the other hand, anomaly-based ID systems determine what is normal traffic within a network and reports abnormal traffic behavior. This paper will describe a methodology towards developing a more-robust Intrusion Detection System through the use of data-mining techniques and anomaly detection. These data-mining techniques will dynamically model what a normal network should look like and reduce the false positive and false negative alarm rates in the process. We will use classification-tree techniques to accurately predict probable attack sessions. Overall, our goal is to model network traffic into network sessions and identify those network sessions that have a high-probability of being an attack and can be labeled as a \"suspect session.\" Subsequently, we will use these techniques inclusive of signature detection methods, as they will be used in concert with known signatures and patterns in order to present a better model for detection and protection of networks and systems."]},{"key":"dc:format","label":"Dc Format","values":["application/pdf"]},{"key":"dc:title","label":"Title","values":["Session-based Intrusion Detection System To Map Anomalous Network Traffic"]}]}],"canonical_facts":{"dc:contributor":["Wang, Morgan"],"dc:creator":["Caulkins, Bruce"],"dc:description":["<p>If this is your thesis or dissertation, and want to learn how to access it or for more information about readership statistics, contact us at <a href=\"mailto:STARS@ucf.edu\">STARS@ucf.edu</a></p>","Doctor of Philosophy (Ph.D.)","College of Arts and Sciences","Modeling and Simulation"],"dc:description.abstract":["Computer crime is a large problem (CSI, 2004; Kabay, 2001a; Kabay, 2001b). Security managers have a variety of tools at their disposal -- firewalls, Intrusion Detection Systems (IDSs), encryption, authentication, and other hardware and software solutions to combat computer crime. Many IDS variants exist which allow security managers and engineers to identify attack network packets primarily through the use of signature detection; i.e., the IDS recognizes attack packets due to their well-known \"fingerprints\" or signatures as those packets cross the network's gateway threshold. On the other hand, anomaly-based ID systems determine what is normal traffic within a network and reports abnormal traffic behavior. This paper will describe a methodology towards developing a more-robust Intrusion Detection System through the use of data-mining techniques and anomaly detection. These data-mining techniques will dynamically model what a normal network should look like and reduce the false positive and false negative alarm rates in the process. We will use classification-tree techniques to accurately predict probable attack sessions. Overall, our goal is to model network traffic into network sessions and identify those network sessions that have a high-probability of being an attack and can be labeled as a \"suspect session.\" Subsequently, we will use these techniques inclusive of signature detection methods, as they will be used in concert with known signatures and patterns in order to present a better model for detection and protection of networks and systems."],"dc:format":["application/pdf"],"dc:identifier":["CFE0000906"],"dc:identifier.uri":["https://stars.library.ucf.edu/etd/539"],"dc:language":["English"],"dc:subject":["Data Mining","Intrusion Detection Systems","Anomaly Detection","Network Modeling","Categorical Data Analysis"],"dc:title":["Session-based Intrusion Detection System To Map Anomalous Network Traffic"],"dc:type":["Doctoral Dissertation (Open Access)"]},"updated_at":"2026-07-24T05:08:59Z"}