Yüksek LisansAçık Erişim

Smart intrusion detection systems

2021
0 görüntülenme
0 i̇ndirme
Danışman: Süleyman Kardaş

Özet (EN)

Information and Communication Technologies have become an inseparable part of the people who take every part of our lives. This is expected to increase in our lives. It is natural for those who want to use it for their own purposes because of the fact that technology is so intertwined with our lives. In case of not taking necessary precautions against the many benefits of technology, it can cause irreparable results with the effect of others. In particular, attackers try to infiltrate or become useless in systems such as Banking, Energy, and Transportation, which are the most influential areas of society. For the attacker, motivation can sometimes be Money and sometimes glory. It is a fact that everyone has accepted that there is a security problem everywhere. For this reason, the USOM has been established across the country for total cyber-wars, while institutions are creating their own cyber-incident intervention teams (SOME). A cyber attack is an assault launched by cybercriminals using one or more devices against a single or multiple devices or networks. A cyber attack can disable system, steal data, or alter data. Cyber attackers apply to various technical and social engineering ways to access the target system(s). Intrusion Detection Systems (IDS) is one of the security components used to detect potential attacks. IDS systems generally try to detect attacks in 3 different ways. Signature Based IDS: This intrusion detection system compares the existing malware database with any abnormalities in the network. Anomaly Based IDS: User profiles are created in this intrusion detection system. It is interpreted as an attack in case of going out of these profiles. Protocol Analysis IDS: Protocol activities are profiled. When a suspicious activity is encountered, it is compared to existing profiles. KDD’99: KDD’99 is a data set used to design models for intrusion detection systems. This data set consists of 42 columns and 4,9402,000 rows. The attack in the data set can be defined in 4 main categories. DoS: denial-of-service is the rendering of a device on the network that cannot serve real users by consuming system resources. Example attack: syn flood. R2L: Attempt to connect to a system without access. Example attack: guessing password. U2R: It is the attack type to obtain admin or root user rights while having normal user rights. Example attack: buffer overflow. Probing: This attack collects information about the target device. This information includes open ports, valid IP addresses, services running on it, operating system installed, and so on. Example attack: port scanning. In this thesis, the attacks in the KDD’99 data set used in Intrusion Detection systems will be categorized and attack statistics and information about these attacks will be given. In addition, system models that will detect an attack that can be performed by using Artificial Neural Networks (ANN) and Decision Tree algorithms, which are among the supervised learning models, have been made in real time and with high performance.

Yazar

Dr. Hanifi Toprak

Bu Yayına Nasıl Atıf Yapılır

Hanifi Toprak (Master Thesis). Smart intrusion detection systems, 2021, Batman University.

Lisans

Tüm Hakları Saklıdır

Bu eser belirtilen lisans koşulları altında paylaşılmaktadır.

Batman University tezlerinden daha fazlası