Deep packet inspection methods for network intrusion detection and application classification
Bu tez size mi ait?
Bu kayıt toplu arşivden geldi. Sizinse profilinize bağlayın.
Özet (EN)
Deep packet inspection methods have become more sophisticated with the rapidly developing technology. To understand the condition of the network, many different packet inspection techniques have been evolved. Newly developing machine learning methods have been used recently on these systems. The aim is to know which type of traffic is running through the network. In this thesis, different deep packet inspection methods are proposed to detect malicious traffic and find the applications running on the network. Time-series and flow-based methods are proposed to accomplish these tasks. Novel feature sets are constructed to execute these methods. Greedy algorithm which finds an upper bound for the distance between the probability distributions with different sizes is utilized in feature extraction process. The extracted features can be divided into two categories which are statistical features and payload-based features. Packet header values such as IP addresses are used to derive statistical features. Also, payload portion of packets are used to extract novel payload--based features. The feature sets are used with decision tree models in supervised learning to execute detection procedures. Proposed approaches are used in network intrusion detection and network application classification tasks. For network intrusion detection, performance evaluation is given by using different publicly available well-known intrusion detection data sets consisting of different types of attacks. For network application classification, a data set consisting of real-world network traces from popular applications is used. Simulation results show that the proposed flow-based approaches have good performance in fulfilling these tasks.
Yazar
Çağatay Ateş
Kurum
Boğaziçi University
Elektrik Elektronik Mühendisliği Bilim Dalı
Bu Yayına Nasıl Atıf Yapılır
Çağatay Ateş (Master Thesis). Deep packet inspection methods for network intrusion detection and application classification, 2022, Boğaziçi University.
Anahtar Kelimeler
Lisans
Tüm Hakları Saklıdır
Bu eser belirtilen lisans koşulları altında paylaşılmaktadır.
Boğaziçi University tezlerinden daha fazlası
- Investigating the factors affecting the acceptance of generative artificial intelligence in business intelligence applications(2025)
- Nükleer güç, emek ve çevre: Akkuyu NGS(2023)
- Behind the gallows: Capital punishment, law, and legislative performance in Turkey (1926-1990)(2025)
- Exploring the values for nature, nature connectedness, pro-environmental behaviour, and well-being: A case study on urban park visitors in Istanbul(2025)
- An assessment on the role of regional development agencies in environmental governance in Türkiye: A case study on Thrace Region(2025)
- Political ecology of milk production in Türkiye: Changing practices, rural livelihoods, and dairy animals(2025)