Lossy network compression for distributed network intrusion detection applications

dc.contributor.advisorHammell, Robert J., II
dc.contributor.authorSmith, Sidney Charles
dc.contributor.departmentTowson University. Department of Computer and Information Sciencesen_US
dc.date.accessioned2025-09-02T16:49:59Z
dc.date.issued2022-12-15
dc.description(D.Sc.) -- Towson University, 2019en_US
dc.description.abstractIn distributed network intrusion detection applications, it is necessary to transmit data from the remote sensors to the central analysis systems. Transmitting all the data captured by the sensor would place an unacceptable demand on the bandwidth available to the site. Most applications address this problem by sending only alerts or summaries; however, these alone do not always provide the analyst with enough information to truly understand what is happening on the network. Lossless compression techniques alone are not suffcient to address the bandwidth demand. This dissertation presents research into lossy compression techniques. It explores several ways in which the maliciousness of network traffc may be rated including entropy, magnitude, fow position, and a combination of N-grams and Bloom flters. These rating methods are combined into a tainted fow rating system. This tainted fow method was used to compress synthetic and competition data sets from 1998 until 2017 to a small percentage of their original size without signifcation loss of Snort alerts.en_US
dc.description.urihttps://archives.towson.edu/Documents/Detail/lossy-network-compression-for-distributed-network-intrusion-detection-applications/345212en_US
dc.format.extentxix, 215 pagesen_US
dc.genredissertationsen_US
dc.identifierdoi:10.13016/m2ww8c-dhv1
dc.identifier.otherDSP2019Smith
dc.identifier.urihttp://hdl.handle.net/11603/40130
dc.language.isoen_USen_US
dc.rightsThere are no restrictions on access to this document. An internet release form signed by the author to display this document online is on file with Towson University Special Collections and Archives.en_US
dc.titleLossy network compression for distributed network intrusion detection applicationsen_US
dc.typeTexten_US

Files

Original bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
DSP2019Smith_Redacted.pdf
Size:
3.67 MB
Format:
Adobe Portable Document Format
Description:
Smith Dissertation

License bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
license.txt
Size:
1.45 KB
Format:
Item-specific license agreed upon to submission
Description: