Search or add a thesis

Advanced Search (Beta)
Home > Improving Anomaly Detection Performance Using Information Theoretic and Machine Learning Tools

Improving Anomaly Detection Performance Using Information Theoretic and Machine Learning Tools

Thesis Info

Access Option

External Link

Author

Ashfaq, Ayesha Binte

Program

PhD

Institute

National University of Sciences & Technology

City

Islamabad

Province

Islamabad

Country

Pakistan

Thesis Completing Year

2014

Thesis Completion Status

Completed

Subject

Computer Science

Language

English

Link

http://prr.hec.gov.pk/jspui/bitstream/123456789/2880/1/2270S.pdf

Added

2021-02-17 19:49:13

Modified

2024-03-24 20:25:49

ARI ID

1676727774576

Asian Research Index Whatsapp Chanel
Asian Research Index Whatsapp Chanel

Join our Whatsapp Channel to get regular updates.

Similar


Anomaly detection systems (ADSs) were proposed more than two decades ago and since then considerable research efforts have been vested in designing and evaluating these systems. However, accuracy in terms of detection and false alarm rates, has been a major limiting factor in the widespread deployment of these systems. Hence, in this thesis we (i) Propose and evaluate information theoretic techniques to improve the performance of existing general-purpose anomaly detection systems; (ii) Design and evaluate a novel and specific-purpose machine learning-based anomaly detec- tion solution for bot detection; (iii) Stochastically model general-purpose anomaly detection systems and show that these systems are inherently susceptible to param- eter estimation attacks; and (iv) Propose novel design philosophies to combat these attacks. To improve the performance of current general-purpose anomaly detection systems, we propose (i) a feature space slicing framework; and (ii) a multi-classifier ADS. The feature space slicing framework operates as a pre-processor, that segregates the feature instances at the input of an ADS. We provide statistical analysis of mixed traffic highlighting that there are two factors that limit the performance of current ADSs: high volume of benign features; and attack instances that exhibit strong similarity with benign feature instances. To mitigate these accuracy limiting factors, we propose a statistical information theoretic framework that segregates the ADS feature space into multiple subspaces before anomaly detection. Thorough evaluations on real-world traffic datasets show that considerable performance improvements can be achieved by judiciously segregating feature instances at the input of a general-purpose ADS. The multi-classifier ADS, on the other hand, defines a standard deviation normalized entropy-of-accuracy based post-processor that judiciously combines outputs of diverse general-purpose anomaly detection classifiers, thus building on their strengths and mitigating their weaknesses. Evaluations on diverse datasets show that the proposed technique provides significant improvements over existing techniques. During the course of this research, the threat landscape changed considerably with botnets emerging as the most potent threat. However, existing general-purpose anomaly detection systems are largely ineffective in detecting this evolving threat be- cause botnets are distinctively different from their predecessors. Since botnets follow a somewhat invariant lifecycle, instead of pure behavior-based solutions, current bot detection tools employ the bot lifecycle for detection. However, these specific-purpose tools use rigid rule-based detection logic that falls short of providing acceptable ac- curacy with evolving botnet behavior [1]. Extending the design philosophy of this thesis, we propose a post-processing detection logic, for specific-purpose bot detec- tion. The proposed post-processor models the high level bot lifecycle as a Bayesian network. Experimental evaluations on diverse real-world botnet traffic datasets show that the use of Bayesian inference based post-processor provides considerable perfor- mance improvements over existing approaches. Lastly, we stochastically model a few existing general-purpose anomaly detection systems and demonstrate that these systems are highly susceptible to parameter es- timation attacks. Since current day malware is becoming increasingly stealthy and difficult to mine in overwhelming volumes of benign traffic, we argue that anomaly detection systems need to be significantly redesigned to cope with the evolving threat landscape. To this end, we propose cryptographically-inspired and moving target based ADS design philosophies. The crypto-inspired ADS design aims at randomiz- ing the learnt normal network profile while the moving target-based ADS design ran- domizes the feature space employed by an ADS for anomaly detection. We provide some preliminary evaluations that show that randomizing ADS parameters greatly improves the robustness of anomaly detection systems against parameter estimation attacks.
Loading...
Loading...

Similar Books

Loading...

Similar Chapters

Loading...

Similar News

Loading...

Similar Articles

Loading...

Similar Article Headings

Loading...

بے سہاروں کا یہاں بوجھ اُٹھانے کے لیے

بے سہاروں کا یہاں بوجھ اُٹھانے کے لیے
کوئی تیار نہیں اپنا بنانے کے لیے

پیار ہر ایک سے کرنا ہی مری دعوت ہے
میرا پیغامِ محبت ہے زمانے کے لیے

کیا ہوا تجھ کو ترا یار اگر چھوڑ گیا
میں جو حاضر ہوں ترے ناز اُٹھانے کے لیے

میں نے جس شخص کا ہر وقت بھلا سوچا ہے
وہ ہے بے تاب مری خاک اُڑانے کے لیے

گو کہ مشکل ہے کہ تائبؔ جی سکوں حاصل ہو
ہم تو زندہ ہیں فقط رنج اُٹھانے کے لیے

إستراتيجية التفاؤل في ضوء قصيدة فلسفة الحياة لإيليا أبو ماضي

Regarding life, people’s thoughts have always been different. This is because of their personal opinions and social and political life that greatly affects human lives. Some people lead a joyful and content life. They think life is full of joys and happiness. Therefore, they always remain hopeful about it; and thus lead a happy life. These optimists always search the positive aspects of life; and shun themselves away from the negative aspects which blacken life. Amongst such people, one is Elia Abu Madi who seems to have adopted the positive and pleasurable aspect of life and invites others to do so. He is of the view that happiness is in human’s hand. If he wants, he can bring himself happiness. This article describes the mentioned strategy of this great poet that he has presented in his poem “The Philosophy of Life”.

Novel Materials for Dye Sensitized Solar Cells

Dye sensitized solar cells (DSSCs) being third generation photovoltaics are inexpensive renewable energy resource and recently been a hot topic of research. The objective of the present research work was to develop photoanode materials for low cost efficient DSSCs. This thesis presents some novel materials for the photoanode including semiconductor material with different nanostructures such as nanoparticles, nanoflowers and nanorods and new sensitizers. Synthesis method of titanium dioxide nanoflowers is reported here. Such hierarchical morphology led to the improved device performance due to greater absorption of light through scattering; a novel photoanode with one dimensional sandwich configuration of ZnO/Au/TiO2, incorporating plasmon resonance and charging effects of Au nanoparticles for enhanced efficiency in DSSCs. New metal free calixarene sensitizers with directed flow of electrons are also studied for DSSCs. Titania nanoflowers are highly desirable in light driven applications due to their large surface area and greater light absorption capabilities. Microwave synthesis of nanomaterials is an energy efficient and quick method. Microwave treatment of titania nanopowders under alkaline conditions is carried out to see the effect of treatment duration. An instant, simple, inexpensive and environment friendly method of preparing titanium dioxide nanoflowers or hierarchical nanostructures (HNSs) is thus achieved. Production of sub-micron sized HNSs without any surfactant or hydrofluoric acid is discovered. From FESEM and TEM analysis the titania nanoflowers are found to be made of few nanometers thick radially arranged nanosheets. XRD and Raman spectra reveal no phase change during the microwave treatment. The mechanism of formation of these hierarchical nanostructures involves sheet formation under strong alkaline conditions and their radial growth under the effect of microwave radiation. The hierarchical morphology provides huge surface area for maximum exposure for light driven reactions and 3 D folding morphology allows further scattering of light to get its maximum utilization. This is evident in improved DSSC performance with synthesized nanoflowers. The HNSs produced in a time as short as 5 minutes show improvement in DSSC efficiency by about 216%. vii One dimensional nanostructures of TiO2 and ZnO have also been vastly studied for application in DSSCs. As a novelty in configuration of 1D core/shell nanostructures, the effect of Au nanoparticles inclusion as a sandwiched layer is studied. The sputter coated gold nanolayers of various sizes are applied over ZnO nanorods grown by seed assisted route. 1D Au/ZnO nanoarrays are covered with a few nanometers thick spin coated TiO2 film to make TiO2/Au/ZnO sandwich nanorod arrays. The uniform morphology and dimensions of the nanorod arrays are studied by SEM. HRTEM studies depict the Au nanoparticle size and distribution within the sandwich nanorods and they are found to be embedded at the interface of ZnO/TiO2 coreshell nanorods. The UV/Vis spectra reveal the plasmon resonance effects due to Au nanoparticles, which are also improving the solar cell efficiencies. The observed enhancement in the photocurrent density is attributed to the Localized Surface Plasmon Resonance (LSPR) effects due to sputter coated Au layers. An increase in the open circuit voltage of DSSCs is also observed due to Fermi level alignment between the Au bridged ZnO and TiO2 in the photoanodes of devices. With 2nm sputter coated Au in TiO2/Au/ZnO 1D nanostructures, a relative efficiency enhancement factor of 2.05 is achieved. Further in search of new inexpensive materials for DSSCs, a new class of metal free Donor-π-bridge-Acceptor (D-π-A) dyes based on basket shaped molecules “calixarenes” is introduced for DSSCs. As in calixarenes the flow of electrons is directed along the length of the molecules by resonance and induction effects and there is no conjugation around the molecular cup. This fact can prevent the recombination of charge carriers to a great extent. p-(6-chloro-2- benzothiazolylazo)calix[4]arene (pcb calix) and p-(1,3,4-thiadiazol-2-thiol-5- ylazo)-calix[4]arene (ptt calix) are synthesized and after characterization by FTIR, UV/Vis, NMR spectroscopy and cyclic voltametry are employed in DSSCs to sensitize titania. The HOMO LUMO levels of the dyes are found consistent with the requirement of DSSCs. An efficiency of 0.3% and 0.47% is achieved with dyes pcb-calix and ptt-calix respectively. The attachment of better absorbing chromophores to calixarene can result in obtaining better efficiencies in DSSCs.