Fulltext available Open Access
License: 
Title: Analysis of available Data Mining Algorithms to detect Advanced Persistent Threats (APT)
Language: German
Authors: Brülhart, Cornelia 
Issue Date: 17-Jan-2017
Abstract: 
Ziel dieser Bachlorarbeit ist das Entwickeln einer Methodenkette, welche Funktionen aus dem Bereich des Data Mining beinhaltet, um fortgeschrittene, andauernde Bedrohungen aufzudecken. Sowohl PDNS als auch NetFlow Logdateien werden hierbei mit einer Reihe an Perl Skripten transformiert und vorverarbeitet, um anschließend in einem Data Mining Programm (Weka) mit einem Algorithmus ausgewertet zu werden. Die Angriffs Detektion wird mithilfe eines Ampel-Konzeptes realisiert, welches IP Adressen nach ihrem Grad des Angriffsverhalten klassiffziert und in Listen speichert.

The objective of this thesis is to determine a chain of different methods from the field of data mining, for the detection of advanced persistent threats. For this, both PDNS and NetFlow data log files are examined with multiple Perl scripts for preprocessing and data transformation purposes, as well as inserted into a data mining tool (Weka) to apply algorithms for knowledge discovery. To aid the detection of attacks, a traffc light concept for suspicious communication behaviour is being presented, which yields the automated developing of several lists containing IP addresses with varying levels of suspiciousness.
URI: http://hdl.handle.net/20.500.12738/7805
Institute: Department Informatik 
Type: Thesis
Thesis type: Bachelor Thesis
Advisor: Kossakowski, Klaus-Peter  
Referee: Zukunft, Olaf 
Appears in Collections:Theses

Files in This Item:
File Description SizeFormat
Cornelia_Bruelhart_Thesis.pdf1.21 MBAdobe PDFView/Open
Show full item record

Page view(s)

135
checked on Apr 23, 2024

Download(s)

182
checked on Apr 23, 2024

Google ScholarTM

Check

HAW Katalog

Check

Note about this record


Items in REPOSIT are protected by copyright, with all rights reserved, unless otherwise indicated.