polito.it
Politecnico di Torino (logo)

Design and engineering of system for large-scale Internet Traffic Visualisation

Claudia Carletti

Design and engineering of system for large-scale Internet Traffic Visualisation.

Rel. Marco Mellia, Idilio Drago. Politecnico di Torino, Corso di laurea magistrale in Communications And Computer Networks Engineering (Ingegneria Telematica E Delle Comunicazioni), 2019

[img]
Preview
PDF (Tesi_di_laurea) - Tesi
Document access: Anyone
Licenza: Creative Commons Attribution Non-commercial No Derivatives.

Download (3MB) | Preview
Abstract:

Nowdays, implement intrusion detection solutions in network environments is always more important. One way, is by using an anomaly detection approach, which relies on the concept of anomaly as deviation from the "normal" behaviour. Traditional anomaly detection systems aim to detect any deviation in the traffic, while in this work we want to focus only on the most relevant ones. Moreover, some anomaly detection techniques could fail in cases like ports with a highly day-night effect in the traffic trend. So the proposed framework aims, in an automated way, to extract, aggregate and visualize meaningful features useful to spot anomalies inside big amount of data. These features are traffic volume, number of unique source IP addresses and number of unique destination IP addresses. We start with traces of real tcp network traffic previously captured, they are processed exploiting the big data approach and, in this way, the network features are aggregated in time series per destination port. The time series are stored in a proper database and then retrived to be visualized. Also, they are analyzed with a forecasting tool, that allows us to spot anomalies as changes in the trend and as dots falling outside the forecasted uncertainty interval. By applying the full process to our dataset, anomalies in the trends are reported. Once an anomaly is detected, it can be investigated to identify the threat.

Relators: Marco Mellia, Idilio Drago
Academic year: 2018/19
Publication type: Electronic
Number of Pages: 67
Subjects:
Corso di laurea: Corso di laurea magistrale in Communications And Computer Networks Engineering (Ingegneria Telematica E Delle Comunicazioni)
Classe di laurea: New organization > Master science > LM-27 - TELECOMMUNICATIONS ENGINEERING
Aziende collaboratrici: UNSPECIFIED
URI: http://webthesis.biblio.polito.it/id/eprint/11695
Modify record (reserved for operators) Modify record (reserved for operators)