Modeling and Analysis of Advanced Intrusion Prevention System Using Distributed Host Datasets for Anomaly Detection
摘要
This study proposes implementing a comprehensive framework for digital infrastructure, designed for securing large Enterprise networks. This study aims to analyze the existing mechanisms for preventing emerging cyber-attacks by analyzing the patterns associated with potential cyber-attacks, leading insights for future behavior and detection of those attacks, with the use of customized open-source security tools and the development of a few new tools and self-developed scripts/code for centralized solution for infrastructure security needs. This research further proposes data analysis approaches and tools to evaluate datasets derived from Honeynets and from actual servers/machines, specifically focusing on attackers and malicious traffic from hosts. The ultimate goal is to provide additional critical information to IT and security administrators i.e.: motives behind attacks, communication methods, attack mechanism, the timing of system attacks, and the subsequent actions performed by attackers after compromising a system.