Title: A Cumulative Sum Technique for Network Cyber Intrusion Detection

Year of Publication: Dec - 2017
Page Numbers: 7-11
Authors: Dimitris Sklavounos, George Paraskevopoulos and Aloysius Edoh
Conference Name: The Third International Conference on Information Security and Digital Forensics (ISDF2017)
- Greece


The present work proposes a mechanism of denial of service (DoS) intrusion detection, by examining changes in mean of the UDP and ICMP source bytes. The detection mechanism utilized for this purpose is the tabular cumulative sum (CUSUM) chart and the experimental dataset is the NSL-KDD Dataset. Two cases were evaluated. In the first case intrusion occurred in the UDP packets while in the second case the intrusion occurred in UDP and ICMP packets. In both cases, a shift in the source bytes mean value took place after the intrusion, and it was clearly depicted in the CUSUM chart. Thus, the intrusion detection in both cases was made successfully.