{"id":{"repo_id":"uiuc","oai_identifier":"oai:www.ideals.illinois.edu:2142/105109"},"canonical_url":"https://search.dev.ndltd.org/etd/uiuc/oai:www.ideals.illinois.edu:2142/105109","repository":{"repo_id":"uiuc","name":"University of Illinois - Urbana-Champaign","base_url":"https://www.ideals.illinois.edu/oai-pmh"},"display":{"title":"Anomaly detection using network metadata","abstract":"Networks are traditionally conﬁgured manually by operators who can potentially introduce misconﬁgurations, exposing the network to security risks. Furthermore, as network complexity grows it becomes harder to track anomalous activity in networks, especially for conﬁguration changes which may go unnoticed unless they have an immediate impact on network operation. Existing techniques for detecting anomalies rely on inspecting irregular patterns in network traﬃc or conﬁguration ﬁles. In this work, we present a preliminary framework which utilizes network metadata for detecting anomalies across enterprise networks. Network metadata helps describe properties of a network that may not be expressed by traﬃc data, and provides an additional metric to evaluate the overall health of a network. Examples of network metadata include software version and interface status for each device in a network. We perform statistical analysis on a combination of network data plane and metadata features in order to detect anomalies as close as possible to the network’s actual behavior. Using a private enterprise dataset, we were able to analyze network metadata to identify anomalous trends which may render a network vulnerable to security threats.","abstract_html":"Networks are traditionally conﬁgured manually by operators who can potentially introduce misconﬁgurations, exposing the network to security risks. Furthermore, as network complexity grows it becomes harder to track anomalous activity in networks, especially for conﬁguration changes which may go unnoticed unless they have an immediate impact on network operation. Existing techniques for detecting anomalies rely on inspecting irregular patterns in network traﬃc or conﬁguration ﬁles. In this work, we present a preliminary framework which utilizes network metadata for detecting anomalies across enterprise networks. Network metadata helps describe properties of a network that may not be expressed by traﬃc data, and provides an additional metric to evaluate the overall health of a network. Examples of network metadata include software version and interface status for each device in a network. We perform statistical analysis on a combination of network data plane and metadata features in order to detect anomalies as close as possible to the network’s actual behavior. Using a private enterprise dataset, we were able to analyze network metadata to identify anomalous trends which may render a network vulnerable to security threats.","abstract_has_math":false,"creators":["Khan, Hassan Shahid"],"institution":"University of Illinois at Urbana-Champaign","degree_name":"M.S.","degree_level":"Thesis","degree_discipline":"Computer Science","degree_department":null,"school":null,"contributors":["Caesar, Matthew"],"advisors":[],"committee_chairs":[],"committee_members":[],"year":2019,"date_issued":"2019-08-23T20:44:14Z","date_published":"2019-08-23T20:44:14Z","updated_at":"2026-07-22T22:24:44Z","subjects":["network verification","network metadata","anomaly detection","security","network security"],"languages":["en"],"rights":["Copyright 2017 Hassan Shahid Khan"],"rights_urls":[],"identifier_entries":[]},"links":{"outbound_url":"http://hdl.handle.net/2142/105109","outbound_label":"Handle","outbound_source":"dc:identifier"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor","label":"Contributor","values":["Caesar, Matthew"]},{"key":"dc:creator","label":"Author","values":["Khan, Hassan Shahid"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date","label":"Dc Date","values":["2019-08-23T20:44:14Z","2021-08-24T09:15:10Z","2017-04-19","2017-05"]},{"key":"dc:type","label":"Dc Type","values":["text"]},{"key":"thesis:degree_discipline","label":"Discipline","values":["Computer Science"]},{"key":"thesis:degree_level","label":"Degree Level","values":["Thesis"]},{"key":"thesis:degree_name","label":"Degree Name","values":["M.S."]},{"key":"thesis:institution_name","label":"Thesis Institution Name","values":["University of Illinois at Urbana-Champaign"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["network verification","network metadata","anomaly detection","security","network security"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:language","label":"Dc Language","values":["en"]},{"key":"dc:rights","label":"Dc Rights","values":["Copyright 2017 Hassan Shahid Khan"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier","label":"Identifier","values":["http://hdl.handle.net/2142/105109"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description","label":"Description","values":["Networks are traditionally conﬁgured manually by operators who can potentially introduce misconﬁgurations, exposing the network to security risks. Furthermore, as network complexity grows it becomes harder to track anomalous activity in networks, especially for conﬁguration changes which may go unnoticed unless they have an immediate impact on network operation. Existing techniques for detecting anomalies rely on inspecting irregular patterns in network traﬃc or conﬁguration ﬁles. In this work, we present a preliminary framework which utilizes network metadata for detecting anomalies across enterprise networks. Network metadata helps describe properties of a network that may not be expressed by traﬃc data, and provides an additional metric to evaluate the overall health of a network. Examples of network metadata include software version and interface status for each device in a network. We perform statistical analysis on a combination of network data plane and metadata features in order to detect anomalies as close as possible to the network’s actual behavior. Using a private enterprise dataset, we were able to analyze network metadata to identify anomalous trends which may render a network vulnerable to security threats.","Submission published under a 24 month embargo labeled 'Closed Access', the embargo will last until 2019-05-01","The student, Hassan Shahid Khan, accepted the attached license on 2017-04-17 at 11:08.","The student, Hassan Shahid Khan, submitted this Thesis for approval on 2017-04-17 at 11:16.","This Thesis was approved for publication on 2017-04-19 at 12:51.","DSpace SAF Submission Ingestion Package generated from Vireo submission #10800 on 2019-08-22 at 16:17:28","Made available in DSpace on 2019-08-23T20:44:14Z (GMT). No. of bitstreams: 2 KHAN-THESIS-2017.pdf: 1274782 bytes, checksum: 34a30a2d974be27b1751451cd27193ee (MD5) LICENSE.txt: 4215 bytes, checksum: d70afb6d720e09ee7d5ac6dddadadc33 (MD5) Previous issue date: 2017-04-19","Embargo set by: Seth Robbins for item 112228 Lift date: 2021-08-23T20:44:50Z Reason: Author requested closed access (OA after 2yrs) in Vireo ETD system","Embargo set by: Seth Robbins for item 112228 Lift date: 2021-08-23T20:46:41Z Reason: Author requested closed access (OA after 2yrs) in Vireo ETD system","Embargo set by: Seth Robbins for item 112228 Lift date: 2021-08-23T20:47:38Z Reason: Author requested closed access (OA after 2yrs) in Vireo ETD system","Embargo set by: Seth Robbins for item 112228 Lift date: 2021-08-23T20:48:32Z Reason: Author requested closed access (OA after 2yrs) in Vireo ETD system","Limited Restriction Lifted for Item 112228 on 2021-08-24T09:15:10Z."]},{"key":"dc:format","label":"Dc Format","values":["application/pdf"]},{"key":"dc:title","label":"Title","values":["Anomaly detection using network metadata"]}]}],"canonical_facts":{"dc:contributor":["Caesar, Matthew"],"dc:creator":["Khan, Hassan Shahid"],"dc:date":["2019-08-23T20:44:14Z","2021-08-24T09:15:10Z","2017-04-19","2017-05"],"dc:description":["Networks are traditionally conﬁgured manually by operators who can potentially introduce misconﬁgurations, exposing the network to security risks. Furthermore, as network complexity grows it becomes harder to track anomalous activity in networks, especially for conﬁguration changes which may go unnoticed unless they have an immediate impact on network operation. Existing techniques for detecting anomalies rely on inspecting irregular patterns in network traﬃc or conﬁguration ﬁles. In this work, we present a preliminary framework which utilizes network metadata for detecting anomalies across enterprise networks. Network metadata helps describe properties of a network that may not be expressed by traﬃc data, and provides an additional metric to evaluate the overall health of a network. Examples of network metadata include software version and interface status for each device in a network. We perform statistical analysis on a combination of network data plane and metadata features in order to detect anomalies as close as possible to the network’s actual behavior. Using a private enterprise dataset, we were able to analyze network metadata to identify anomalous trends which may render a network vulnerable to security threats.","Submission published under a 24 month embargo labeled 'Closed Access', the embargo will last until 2019-05-01","The student, Hassan Shahid Khan, accepted the attached license on 2017-04-17 at 11:08.","The student, Hassan Shahid Khan, submitted this Thesis for approval on 2017-04-17 at 11:16.","This Thesis was approved for publication on 2017-04-19 at 12:51.","DSpace SAF Submission Ingestion Package generated from Vireo submission #10800 on 2019-08-22 at 16:17:28","Made available in DSpace on 2019-08-23T20:44:14Z (GMT). No. of bitstreams: 2 KHAN-THESIS-2017.pdf: 1274782 bytes, checksum: 34a30a2d974be27b1751451cd27193ee (MD5) LICENSE.txt: 4215 bytes, checksum: d70afb6d720e09ee7d5ac6dddadadc33 (MD5) Previous issue date: 2017-04-19","Embargo set by: Seth Robbins for item 112228 Lift date: 2021-08-23T20:44:50Z Reason: Author requested closed access (OA after 2yrs) in Vireo ETD system","Embargo set by: Seth Robbins for item 112228 Lift date: 2021-08-23T20:46:41Z Reason: Author requested closed access (OA after 2yrs) in Vireo ETD system","Embargo set by: Seth Robbins for item 112228 Lift date: 2021-08-23T20:47:38Z Reason: Author requested closed access (OA after 2yrs) in Vireo ETD system","Embargo set by: Seth Robbins for item 112228 Lift date: 2021-08-23T20:48:32Z Reason: Author requested closed access (OA after 2yrs) in Vireo ETD system","Limited Restriction Lifted for Item 112228 on 2021-08-24T09:15:10Z."],"dc:format":["application/pdf"],"dc:identifier":["http://hdl.handle.net/2142/105109"],"dc:language":["en"],"dc:rights":["Copyright 2017 Hassan Shahid Khan"],"dc:subject":["network verification","network metadata","anomaly detection","security","network security"],"dc:title":["Anomaly detection using network metadata"],"dc:type":["text"],"thesis:degree_discipline":["Computer Science"],"thesis:degree_level":["Thesis"],"thesis:degree_name":["M.S."],"thesis:institution_name":["University of Illinois at Urbana-Champaign"]},"updated_at":"2026-07-22T22:24:44Z"}