{"id":{"repo_id":"uiuc","oai_identifier":"oai:www.ideals.illinois.edu:2142/99375"},"canonical_url":"https://search.dev.ndltd.org/etd/uiuc/oai:www.ideals.illinois.edu:2142/99375","repository":{"repo_id":"uiuc","name":"University of Illinois - Urbana-Champaign","base_url":"https://www.ideals.illinois.edu/oai-pmh"},"display":{"title":"Characterizing university network usage with Active Directory event logs","abstract":"In this thesis, we investigate a university network that uses Active Directory as its authentication system. We get an understanding of the network by analyzing Windows event logs generated at Active Directory domain controllers. We want to see what network activity looks like as a first step in identifying and modeling network lateral movement. We characterize network activity, access behavior, most frequent events encountered, and domain controller usage. We find that the data, covering a week’s time, supports multiple trends. The number of events encountered increases from morning to noon and decreases after mid afternoon. Weekend activity is lower than during weekdays. Over the week of user-generated events, about 85% create 1,000 events or less. Less than 5% of users create more than 10,000 events. The top five events encountered are associated with user sessions (i.e., login, logout, authentication) or Kerberos ticket requests. Most events are generated at the Urbana Domain Controllers. The second largest number of events (although about 15 times smaller) are generated at the DCs that serve only WiFi and VPN.","abstract_html":"In this thesis, we investigate a university network that uses Active Directory as its authentication system. We get an understanding of the network by analyzing Windows event logs generated at Active Directory domain controllers. We want to see what network activity looks like as a first step in identifying and modeling network lateral movement. We characterize network activity, access behavior, most frequent events encountered, and domain controller usage. We find that the data, covering a week’s time, supports multiple trends. The number of events encountered increases from morning to noon and decreases after mid afternoon. Weekend activity is lower than during weekdays. Over the week of user-generated events, about 85% create 1,000 events or less. Less than 5% of users create more than 10,000 events. The top five events encountered are associated with user sessions (i.e., login, logout, authentication) or Kerberos ticket requests. Most events are generated at the Urbana Domain Controllers. The second largest number of events (although about 15 times smaller) are generated at the DCs that serve only WiFi and VPN.","abstract_has_math":false,"creators":["Mitsdarfer, Alex Joseph"],"institution":"University of Illinois at Urbana-Champaign","degree_name":"M.S.","degree_level":"Thesis","degree_discipline":"Electrical & Computer Engr","degree_department":null,"school":null,"contributors":["Bailey, Michael"],"advisors":[],"committee_chairs":[],"committee_members":[],"year":2018,"date_issued":"2018-03-13T15:48:58Z","date_published":"2018-03-13T15:48:58Z","updated_at":"2026-07-22T22:24:37Z","subjects":["Active Directory","Network usage","Network characterization","University network","University network usage","University network characterization","Lateral movement","Event logs","Active Directory event logs"],"languages":["en"],"rights":["Copyright 2017 Alex Mitsdarfer"],"rights_urls":[],"identifier_entries":[]},"links":{"outbound_url":"http://hdl.handle.net/2142/99375","outbound_label":"Handle","outbound_source":"dc:identifier"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor","label":"Contributor","values":["Bailey, Michael"]},{"key":"dc:creator","label":"Author","values":["Mitsdarfer, Alex Joseph"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date","label":"Dc Date","values":["2018-03-13T15:48:58Z","2017-12-06","2017-12"]},{"key":"dc:type","label":"Dc Type","values":["text"]},{"key":"thesis:degree_discipline","label":"Discipline","values":["Electrical & Computer Engr"]},{"key":"thesis:degree_level","label":"Degree Level","values":["Thesis"]},{"key":"thesis:degree_name","label":"Degree Name","values":["M.S."]},{"key":"thesis:institution_name","label":"Thesis Institution Name","values":["University of Illinois at Urbana-Champaign"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["Active Directory","Network usage","Network characterization","University network","University network usage","University network characterization","Lateral movement","Event logs","Active Directory event logs"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:language","label":"Dc Language","values":["en"]},{"key":"dc:rights","label":"Dc Rights","values":["Copyright 2017 Alex Mitsdarfer"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier","label":"Identifier","values":["http://hdl.handle.net/2142/99375"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description","label":"Description","values":["In this thesis, we investigate a university network that uses Active Directory as its authentication system. We get an understanding of the network by analyzing Windows event logs generated at Active Directory domain controllers. We want to see what network activity looks like as a first step in identifying and modeling network lateral movement. We characterize network activity, access behavior, most frequent events encountered, and domain controller usage. We find that the data, covering a week’s time, supports multiple trends. The number of events encountered increases from morning to noon and decreases after mid afternoon. Weekend activity is lower than during weekdays. Over the week of user-generated events, about 85% create 1,000 events or less. Less than 5% of users create more than 10,000 events. The top five events encountered are associated with user sessions (i.e., login, logout, authentication) or Kerberos ticket requests. Most events are generated at the Urbana Domain Controllers. The second largest number of events (although about 15 times smaller) are generated at the DCs that serve only WiFi and VPN.","Submission original under an indefinite embargo labeled 'Open Access'. The submission was exported from vireo on 2018-03-13 without embargo terms","The student, Alex Mitsdarfer, accepted the attached license on 2017-12-05 at 13:15.","The student, Alex Mitsdarfer, submitted this Thesis for approval on 2017-12-05 at 13:37.","This Thesis was approved for publication on 2017-12-06 at 09:50.","DSpace SAF Submission Ingestion Package generated from Vireo submission #11862 on 2018-03-13 at 10:10:55","Made available in DSpace on 2018-03-13T15:48:58Z (GMT). No. of bitstreams: 13 MITSDARFER-THESIS-2017.pdf: 807307 bytes, checksum: 99d14be147a320d0256d2f5692c75f95 (MD5) IEEE_ECE.bst: 61899 bytes, checksum: 7509566d10f8075f0fad3df817415508 (MD5) abs.tex: 1163 bytes, checksum: 9bb8abb898e1d612a412e157b4acf014 (MD5) ack.tex: 263 bytes, checksum: badb060c434a3e1b2dfcb5100d11a66d (MD5) apx.tex: 95607 bytes, checksum: cefe71e13daa163e95203cc665d89acd (MD5) concl.tex: 4032 bytes, checksum: b2b71af299db2a854f50696f8a7473ee (MD5) ecethesis.tex: 5356 bytes, checksum: 47bf7109b5ff4d4444ef0d96dfb84281 (MD5) exper.tex: 59946 bytes, checksum: 08774b0422068abd7f2ffaf5a3ade080 (MD5) intro.tex: 23670 bytes, checksum: 14a1dd3ead54b5a1116f4b3b043218a2 (MD5) related.tex: 8887 bytes, checksum: 1b9c84ef82dfc6296625c70e65086d54 (MD5) thesisrefs.bib: 51081 bytes, checksum: 84e2f8744f945fe9496a43498d047673 (MD5) uiucecethesis09.cls: 22162 bytes, checksum: f7b508a2389c889fd082d4b2526767e7 (MD5) LICENSE.txt: 4212 bytes, checksum: 4cfc67e0cde073cc2ed6889ad3e450e8 (MD5) Previous issue date: 2017-12-06"]},{"key":"dc:format","label":"Dc Format","values":["application/pdf"]},{"key":"dc:title","label":"Title","values":["Characterizing university network usage with Active Directory event logs"]}]}],"canonical_facts":{"dc:contributor":["Bailey, Michael"],"dc:creator":["Mitsdarfer, Alex Joseph"],"dc:date":["2018-03-13T15:48:58Z","2017-12-06","2017-12"],"dc:description":["In this thesis, we investigate a university network that uses Active Directory as its authentication system. We get an understanding of the network by analyzing Windows event logs generated at Active Directory domain controllers. We want to see what network activity looks like as a first step in identifying and modeling network lateral movement. We characterize network activity, access behavior, most frequent events encountered, and domain controller usage. We find that the data, covering a week’s time, supports multiple trends. The number of events encountered increases from morning to noon and decreases after mid afternoon. Weekend activity is lower than during weekdays. Over the week of user-generated events, about 85% create 1,000 events or less. Less than 5% of users create more than 10,000 events. The top five events encountered are associated with user sessions (i.e., login, logout, authentication) or Kerberos ticket requests. Most events are generated at the Urbana Domain Controllers. The second largest number of events (although about 15 times smaller) are generated at the DCs that serve only WiFi and VPN.","Submission original under an indefinite embargo labeled 'Open Access'. The submission was exported from vireo on 2018-03-13 without embargo terms","The student, Alex Mitsdarfer, accepted the attached license on 2017-12-05 at 13:15.","The student, Alex Mitsdarfer, submitted this Thesis for approval on 2017-12-05 at 13:37.","This Thesis was approved for publication on 2017-12-06 at 09:50.","DSpace SAF Submission Ingestion Package generated from Vireo submission #11862 on 2018-03-13 at 10:10:55","Made available in DSpace on 2018-03-13T15:48:58Z (GMT). No. of bitstreams: 13 MITSDARFER-THESIS-2017.pdf: 807307 bytes, checksum: 99d14be147a320d0256d2f5692c75f95 (MD5) IEEE_ECE.bst: 61899 bytes, checksum: 7509566d10f8075f0fad3df817415508 (MD5) abs.tex: 1163 bytes, checksum: 9bb8abb898e1d612a412e157b4acf014 (MD5) ack.tex: 263 bytes, checksum: badb060c434a3e1b2dfcb5100d11a66d (MD5) apx.tex: 95607 bytes, checksum: cefe71e13daa163e95203cc665d89acd (MD5) concl.tex: 4032 bytes, checksum: b2b71af299db2a854f50696f8a7473ee (MD5) ecethesis.tex: 5356 bytes, checksum: 47bf7109b5ff4d4444ef0d96dfb84281 (MD5) exper.tex: 59946 bytes, checksum: 08774b0422068abd7f2ffaf5a3ade080 (MD5) intro.tex: 23670 bytes, checksum: 14a1dd3ead54b5a1116f4b3b043218a2 (MD5) related.tex: 8887 bytes, checksum: 1b9c84ef82dfc6296625c70e65086d54 (MD5) thesisrefs.bib: 51081 bytes, checksum: 84e2f8744f945fe9496a43498d047673 (MD5) uiucecethesis09.cls: 22162 bytes, checksum: f7b508a2389c889fd082d4b2526767e7 (MD5) LICENSE.txt: 4212 bytes, checksum: 4cfc67e0cde073cc2ed6889ad3e450e8 (MD5) Previous issue date: 2017-12-06"],"dc:format":["application/pdf"],"dc:identifier":["http://hdl.handle.net/2142/99375"],"dc:language":["en"],"dc:rights":["Copyright 2017 Alex Mitsdarfer"],"dc:subject":["Active Directory","Network usage","Network characterization","University network","University network usage","University network characterization","Lateral movement","Event logs","Active Directory event logs"],"dc:title":["Characterizing university network usage with Active Directory event logs"],"dc:type":["text"],"thesis:degree_discipline":["Electrical & Computer Engr"],"thesis:degree_level":["Thesis"],"thesis:degree_name":["M.S."],"thesis:institution_name":["University of Illinois at Urbana-Champaign"]},"updated_at":"2026-07-22T22:24:37Z"}