Master'sOpen Access

Design and implementation of a realtime network intrusion detection system

2007
0 views
0 downloads
Advisor: Yrd. Doç. Dr. A. Gökhan Yavuz

Abstract (EN)

Intrusion detection systems consist of two different approaches, anomaly detection and signature based detection. Both approaches have advantages and disadvantages against the other. In this thesis, it is aimed to use both approaches to increase the success rate of the intrusion detection system. It is considered to use the Snort system for the signature based approach. Constantly updating the signatures used in the Snort system and the basic and modular structure of the system allows a real-time and anomaly based system to be built on a Snort structure. To detect anomalies it is considered to use SVM (Support Vector Machines) method. Linux Operating System is used to implement the application because of its open-source structure and the richness of its application developing environment. Keywords: Intrusion, Intrusion detection, Intrusion detection system, Snort, Support vector machine, C4.5, Random Forest, DARPA intrusion detection evaluation data, KDD Cup 99 data

Author

Dr. Erdem Can

How to Cite

Erdem Can (Master Thesis). Design and implementation of a realtime network intrusion detection system, 2007, Yıldız Technical University.

Keywords

License

Tüm Hakları Saklıdır

This work is shared under the specified license terms.

More theses from Yıldız Technical University