90 likes | 230 Views
Multi-Route Anomaly detection using Principal Component Analysis. Adnan Iqbal Superviser Dr. Waqar Mahmood. The concept. Idea is to discover anomalies in the whole network and then to compare these network wide anomalies with those of single route anomalies
E N D
Multi-Route Anomaly detection using Principal Component Analysis Adnan Iqbal Superviser Dr. Waqar Mahmood
The concept • Idea is to discover anomalies in the whole network and then to compare these network wide anomalies with those of single route anomalies • To find out relationship between network wide anomalies and its constituent single route anomalies
Summary • Discover a scheme that can be used to get relationship between network wide anomalies and single route anomalies • Implement the scheme • Perform Regularization of Data • Apply the scheme to suitable routes • Analyze Results • Analysis of Data used in Anomaly Detection
Current Work • Current Work • Study of MIT Lincoln Lab intrusion detection data • The Network • Inside (Air Force Base) • Outside (Internet) • DMZ (Connection) • Data Sets (98, 99, 2000) • 2000 data set (scenario based) • LLDOS 1.0 - Scenario One • LLDOS 2.0.2 - Scenario Two • Windows NT Attack Data Set
Inside Hosts Network 3-1
Future Work • Depends on The out come of MIT Lincoln Lab Data Analysis