Beta
23416

Detecting Abnormal Network Traffic in the Secure Event Management Systems

Article

Last updated: 04 Jan 2025

Subjects

-

Tags

-

Abstract

State-of-the-art intrusion detection and monitoring systems produce hundreds or even thousands of events every day. Unfortunately, most of these events are false positives, or irrelevant and can be considered as background noise, which makes their correlation, analysis and investigation very complicated and resource consuming. This paper attempts to simulate the modeling of background noise using the non-stationary time series analysis with lag smoothing Kalman filter. Then introduce and compare a second technique applying a multi-layered perceptron neural network with back  ropagation network; an approach that is used for the first time in modeling and correlating the background noise. DARPA Dataset is used to analyze and compare both techniques and finally a verification experiment is conducted using a gathered dataset from real network environment.

DOI

10.21608/asat.2011.23416

Keywords

Intrusion Detection, Alert Correlation, Time Series Modeling, Kalman Filtering, Neural network

Authors

First Name

A.

Last Name

Abd Elmomen

MiddleName

-

Affiliation

Senior Security Engineer, France Telecom – Orange Business Services, Cairo, Egypt.

Email

-

City

-

Orcid

-

First Name

A.

Last Name

Bahaa El Din

MiddleName

-

Affiliation

Ph. D. Computer and System Engineering Department – Faculty of Engineering – Ain Shams University – Cairo, Egypt.

Email

-

City

-

Orcid

-

First Name

A.

Last Name

Wahdan

MiddleName

-

Affiliation

Professor, Computer and System Engineering Department – Faculty of Engineering – Ain Shams University – Cairo, Egypt.

Email

-

City

-

Orcid

-

Volume

14

Article Issue

AEROSPACE SCIENCES & AVIATION TECHNOLOGY, ASAT - 14 – May 24 - 26, 2011

Related Issue

4330

Issue Date

2011-05-01

Receive Date

2019-01-02

Publish Date

2011-05-01

Page Start

1

Page End

15

Print ISSN

2090-0678

Online ISSN

2636-364X

Link

https://asat.journals.ekb.eg/article_23416.html

Detail API

https://asat.journals.ekb.eg/service?article_code=23416

Order

102

Type

Original Article

Type Code

737

Publication Type

Journal

Publication Title

International Conference on Aerospace Sciences and Aviation Technology

Publication Link

https://asat.journals.ekb.eg/

MainTitle

Detecting Abnormal Network Traffic in the Secure Event Management Systems

Details

Type

Article

Created At

22 Jan 2023