Home Research
Research
Completed Project : Alert Correlation


Alert correlation is a process that takes as input the alerts produced by one or more intrusion detection sensors and provides a more succinct and high-level view of occurring or attempted intrusions. The main objective is to produce intrusion reports that capture a high-level view of the activity on the network without losing security-relevant information.

 

Read more...
 
Automated Rule Tuning 
      
 Rules are widely used in network management systems. In essence, they allow implementation of the system security policy in a flexible format that can be easily maintained and interpreted by human. However, one of the drawbacks of the rules is the reliance on the user guidance in rule development as well as in their adjustment to the changes in the network environment and security policy.
  
Current Members:
 

Natalia Stakhanova

               
Previous Members:
 

Shah Arif Iqbal

   
Read more...
 
Automatic Discovery and Classification of Network Applications
     
 

Identifying network traffic into different applications is very challenging and is still an issue yet to be solved. In practice, traffic application classification relies to a large extent on the transport layer port numbers, which was an effective way in the early days of the Internet. Port numbers, however, provide very limited information nowadays. An alternative way, currently applied by QRadar, is to examine the payload of network flows and then create signatures for each application.

  
Current Members:
 

Mahbod Tavallaee


 
Previous Members:

Wei Lu  
Read more...
 
Botnet Detection 
      
  Botnets have become the platform of choice for launching attacks and committing fraud on the Internet. A better understanding of Botnets will help to coordinate and develop new technologies to counter this serious security threat.
  
Current Members:
 

Ali Shiravi




Previous Members:
 Wei LuGoaletsa Rammidi  
Read more...
 
Conflict-free IDS Rule Management


Generally, misuse and specification-based approaches are implemented in a form of rule-based intrusion detection system (IDS) that aims to detect attacks by analyzing network traffic against a predefined set of rules. These rules generally describe the various IDS-defined features of the searched traffic (e.g. destination port, payload content, confidence level of the IDS, etc.) and the response action to be deployed in case the observed traffic matches the description.  

Current Members:

 Natalia Stakhanova

 

 

 

Read more...
 

 

Data Visualization
      
  Visualization, in the security sense, is the process of generating a picture based on log records. It defines how the log records are mapped into a visual representation.
  
Current Members:
 

Ali Shiravi

Hadi Shiravi                     
Previous Members:
 

Iosif-Viorel Onut

   
Read more...
 

 

Network Anomaly Detection  
     
 

Anomaly detection systems flag observed activities that deviate significantly from the established normal usage profiles as anomalies. This paradigm takes the attitude that something that is abnormal is probably suspicious.

  
Current Members:
 

Mahbod Tavallaee


 
Previous Members:
 

Wei Lu

  
Read more...
 
Prediction of Network Attacks
      
 Predictability of network state has received a considerable attention in many domains, including adaptive applications, congestion control, admission control, wireless and network management. Although in the past decade a range of prediction algorithms have proposed, they generally present isolated efforts focused of various traffic characteristics and do not constitute a systematic approach to prediction of network state.
  
Current Members:
 

Natalia Stakhanova

               
Previous Members:
 

Mahsa Kiani

   
Read more...
 
Simulation of Network Attacks
      
  The rapid propagation of Internet into our daily life accompanied by the increase in volume and sophistication of network attacks puts a special emphasis on the security of the network systems. Currently, security modeling and simulation is one of the widely acknowledged methods for network security evaluation.
  
Current Members:
 

Ali Shiravi

Hanli RenNatalia Stakhanova 
Previous Members:
 

Iosif-Viorel Onut

   

 

Read more...
 
UNB Honeynet
      
  In computer terminology, a honeypot is a trap set to detect, deflect or in some manner counteract attempts at unauthorized use of information systems. Generally it consists of a computer, data or a network site that appears to be part of a network but which is actually isolated and protected, and which seems to contain information or a resource that would be of value to attackers.
  
Current Members:
 

 Hanli Ren

Natalia Stakhanova

Previous Members:
    Wei Lu   
Read more...