Abstract
dc:descriptionNetworks are traditionally configured manually by operators who can potentially introduce misconfigurations, exposing the network to security risks. Furthermore, as network complexity grows it becomes harder to track anomalous activity in networks, especially for configuration changes which may go unnoticed unless they have an immediate impact on network operation. Existing techniques for detecting anomalies rely on inspecting irregular patterns in network traffic or configuration files. In this work, we present a preliminary framework which utilizes network metadata for detecting anomalies across enterprise networks. Network metadata helps describe properties of a network that may not be expressed by traffic data, and provides an additional metric to evaluate the overall health of a network. Examples of network metadata include software version and interface status for each device in a network. We perform statistical analysis on a combination of network data plane and metadata features in order to detect anomalies as close as possible to the network’s actual behavior. Using a private enterprise dataset, we were able to analyze network metadata to identify anomalous trends which may render a network vulnerable to security threats.
Degree
thesis:*- Name thesis:degree_name
- M.S.
- Level thesis:degree_level
- Thesis
- Discipline thesis:degree_discipline
- Computer Science
- Grantor
- University of Illinois at Urbana-Champaign
- Year dc:date
- 2019
Author and committee
dc:creator, dc:contributor.*- Author dc:creator
-
- Khan, Hassan Shahid
- Contributors dc:contributor
-
- Caesar, Matthew
Subjects
dc:subject × 5Rights
dc:rights- Statement dc:rights
-
- Copyright 2017 Hassan Shahid Khan
- Language dc:language
- en
Identifiers
dc:identifier.*- Handle dc:identifier
- http://hdl.handle.net/2142/105109
- OAI identifier oai:identifier
- oai:www.ideals.illinois.edu:2142/105109