Improving the Evaluation of Network Anomaly Detection Using a Data Fusion Approach

dc.contributor.advisorNelson, Richard
dc.contributor.advisorMayo, Michael
dc.contributor.advisorMcGregor, Anthony James
dc.contributor.authorLöf, Andreas
dc.date.accessioned2013-10-01T02:12:06Z
dc.date.available2013-10-22T21:12:37Z
dc.date.issued2013
dc.date.updated2013-10-01T02:10:30Z
dc.descriptionAny future extensions or updates will be published as a part of WAND's ongoing research projects: http://research.wand.net.nz
dc.description.abstractCurrently, the evaluation of network anomaly detection methods is often not repeatable. It is difficult to ascertain if different implementations of the same methods have the same performance or the relative performance of different methods. This is in part due to a lack of open implementations, the absence of recent datasets and no common format to express results. A common approach to evaluating a method is to use the Defense Advanced Research Projects Agency (DARPA) 1999 datasets, or a derivative of them, in combination with a different dataset or network capture. The DARPA datasets are relatively old and bear little resemblance to modern day traffic and the other datasets are unlabelled and typically publicly unavailable making it difficult to ascertain the validity of the research evaluated in such a way. This thesis primarily contributes a new evaluation methodology that uses a data fusion based approach that allows for reproducible evaluations with modern datasets. The new methodology incorporates three other contributions: A new way to capture network traces that are fully anonymised yet retains more information than any current network traces and a new trace annotation format and a method for verifying the correctness of the annotations. The DARPA 1999 dataset was used to demonstrate the validity of the approach and an evaluation was performed on a new dataset that has been captured using the methods introduced. In the evaluation we find that methodology is a viable approach forward, but that it comes with a different set of drawbacks than the current state of the art.
dc.format.mimetypeapplication/pdf
dc.format.mimetypeapplication/x-gzip
dc.format.mimetypeapplication/x-gzip
dc.format.mimetypeapplication/x-gzip
dc.format.mimetypeapplication/x-gzip
dc.format.mimetypeapplication/x-gzip
dc.identifier.citationLöf, A. (2013). Improving the Evaluation of Network Anomaly Detection Using a Data Fusion Approach (Thesis, Doctor of Philosophy (PhD)). University of Waikato, Hamilton, New Zealand. Retrieved from https://hdl.handle.net/10289/8041en
dc.identifier.urihttps://hdl.handle.net/10289/8041
dc.language.isoen
dc.publisherUniversity of Waikato
dc.rightsAll items in Research Commons are provided for private study and research purposes and are protected by copyright with all rights reserved unless otherwise indicated.
dc.subjectnetwork anomaly detection
dc.subjectnetwork capture
dc.subjectintrusion detection
dc.subjectdata fusion
dc.titleImproving the Evaluation of Network Anomaly Detection Using a Data Fusion Approach
dc.typeThesis
dspace.entity.typePublication
pubs.place-of-publicationHamilton, New Zealanden_NZ
thesis.degree.disciplineComputer Science
thesis.degree.grantorUniversity of Waikato
thesis.degree.levelDoctoral
thesis.degree.nameDoctor of Philosophy (PhD)
uow.relation.urihttp://wand.net.nz/wits/waikato/8/
uow.relation.urihttp://www.ll.mit.edu/mission/communications/cyber/CSTcorpora/ideval/data/

Files

Original bundle

Now showing 1 - 5 of 6
Loading...
Thumbnail Image
Name:
thesis.pdf
Size:
2.25 MB
Format:
Adobe Portable Document Format
Description:
Main text
Loading...
Thumbnail Image
Name:
traceannotation.tgz
Size:
17.47 KB
Format:
UNIX Tar File Gzipped
Description:
Annotation library
Loading...
Thumbnail Image
Name:
traceannotater.tgz
Size:
60.48 KB
Format:
UNIX Tar File Gzipped
Description:
Annotation conversion tools
Loading...
Thumbnail Image
Name:
annotations.tgz
Size:
42.07 MB
Format:
UNIX Tar File Gzipped
Description:
Network trace annotations
Loading...
Thumbnail Image
Name:
fusion.tgz
Size:
29.32 KB
Format:
UNIX Tar File Gzipped
Description:
Data fusion components

License bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
license.txt
Size:
2.07 KB
Format:
Item-specific license agreed upon to submission
Description: