Welcome to the Bahria University DSpace digital repository. DSpace is a digital service that collects, preserves, and distributes digital material. Repositories are important tools for preserving an organization's legacy; they facilitate digital preservation and scholarly communication.
dc.contributor.author | Usama Ehsan Abbasi, 01-247202-021 | |
dc.date.accessioned | 2023-05-24T07:27:23Z | |
dc.date.available | 2023-05-24T07:27:23Z | |
dc.date.issued | 2023 | |
dc.identifier.uri | http://hdl.handle.net/123456789/15536 | |
dc.description | Supervised by Dr. Kashif Naseer Qureshi | en_US |
dc.description.abstract | Software Defined Networking (SDN) decouples the control and data plane. SDN approach enables the network administrator to respond quickly to the essential requirements from a centralized controller. SDN provides a novel networking structure of network flow management, which has made precise and accurate anomaly detection. In SDN the whole network can be managed by only one command. Hence, if an SDN switch is compromised by the attacker then the whole network can be compromised by the command of an attacker. The problem with the signature-based anomaly detector is that it can be fooled by an unknown attack. However, the conventional machine learning based anomaly identifier resides at central controller may overload the controller, as it is inefficient to process each and every packet at the central controller. This research proposes a 2-stage anomaly identifier by using machine-learning techniques. The 2-stage anomaly identifier approach reduces the packet level processing and anomaly detection at the central controller. For evaluation, the proposed model compares with several supervised machine-learning algorithms by using a publicly available dataset. The experimental result shows support for the DPTCM-KNN algorithm for stage-1 FB (flow-based) anomaly identifier. A decision-tree-based machine learning approach is used for Classification and Regression Tree (CART) for stage-2 PB (packet-based) anomaly identifier and proved that the proposed solution promises a reduction in false positive marked anomalous flow by processing its packets at anomaly identifier stage 2 compared to a single stage anomaly identifier. | en_US |
dc.language.iso | en | en_US |
dc.publisher | Computer Sciences | en_US |
dc.relation.ispartofseries | MS (IS);T-01979 | |
dc.subject | Internet of Things | en_US |
dc.subject | Statistics-Based | en_US |
dc.title | An Efficient Signature and Flow Statistics-Based Anomaly Detection System by Using Software-Defined Networking for the Internet Of Things | en_US |
dc.type | MS Thesis | en_US |