Institutional-Repository, University of Moratuwa.  

Improving the threat detection performance of a network intrusion detection system using A 3-Tier framework

Show simple item record

dc.contributor.advisor Gamage CD
dc.contributor.author Senanayake SDW
dc.date.accessioned 2021
dc.date.available 2021
dc.date.issued 2021
dc.identifier.citation Senanayake, S.D.W. (2021). Improving the threat detection performance of a network intrusion detection system using A 3-Tier framework [Master's theses, University of Moratuwa]. Institutional Repository University of Moratuwa. http://dl.lib.uom.lk/handle/123/21198
dc.identifier.uri http://dl.lib.uom.lk/handle/123/21198
dc.description.abstract Information security is becoming more and more critical for data and information. Network security plays a major role in securing the data and systems from Cyber adversaries. It is crucial to detect the dangers actively and implement defences to protect network infrastructure from Cyber-attackers. In this project, we have introduced a way to optimise the threat detection capabilities using Zeek Network Security Monitor and Weka machine learning application. In fact, we have performed a comprehensive study on the evolution of Intrusion Detection Systems (IDS) using the past literature and identified the factors that contributed to both improved performance and limitations in threat detection. We have designed and developed a Network Security Monitoring (NSM) system prototype using Zeek NSM, Elasticsearch, Filebeat and Kibana Stack(EFK stack) and Weka application. Moreover, our prototype actively performs network surveillance and alerts the user in an event of intrusion. Finally, we have performed a passive machine learning analysis using Random Forrest, K-Nearest Neighbors and Naïve Bayes classifiers on Denial of Service, Reconnaissance and Worm attacks. We have used a sample set of data from the UNSW-NB15 data set for the machine learning analysis activities. Installation and configuration of open-source applications are not always straightforward, and they could be swamped with cumbersome processes. We have provided foolproof, stepwise guidance to perform the installation and configure of the Zeek and EFK stack at the end of this thesis. The authors main objective is to design and develop user-friendly security solutions for threat detection using open-source applications. This project is the initial step to achieve that objective. en_US
dc.language.iso en en_US
dc.subject NETWORK SECURITY en_US
dc.subject NIDS en_US
dc.subject ZEEK NSM en_US
dc.subject WEKA en_US
dc.subject COMPUTER SCIENCE & ENGINEERING -Dissertation en_US
dc.subject COMPUTER SCIENCE -Dissertation en_US
dc.subject INFORMATION TECHNOLOGY -Dissertation en_US
dc.title Improving the threat detection performance of a network intrusion detection system using A 3-Tier framework en_US
dc.type Thesis-Abstract en_US
dc.identifier.faculty Engineering en_US
dc.identifier.degree MSc In Computer Science and Engineering en_US
dc.identifier.department Department of Computer Science and Engineering en_US
dc.date.accept 2021
dc.identifier.accno Th4591 en_US


Files in this item

This item appears in the following Collection(s)

Show simple item record