Thesis Details

Profilování síťových entit pro zlepšení situačního povědomí

Bachelor's Thesis Student: Bolf René Academic Year: 2020/2021 Supervisor: Žádník Martin, Ing., Ph.D.
English title
Profiling of Network Entities to Improve Situational Awareness
Language
Czech
Abstract

Having a good situational awareness is an important part of computer security. Knowing what is connected to the network, where it is located, and who is communicating can help make better and faster decisions when security incidents occur. This thesis is focusing on the profiling of network entities at the device level. More specifically, it focuses on the passive identification of operating systems. Every packet transferred in the network carries a specific information in its packet header that reflects the initial settings of a host's operating system. The set of these information is called the "fingerprint" of an operating system. In the thesis, there is described an implementation of a machine learning classifier using the decision tree method, which uses features from TCP and IP headers. The classifier was evaluated on a data set containing data from real network traffic and has achieved accuracy of 96 % when classifying into 9 classes of operating systems.

Keywords

Situational Awareness, Profiling" operating systems, IP flow, monitoring, operating systemidentification

Department
Degree Programme
Information Technology
Files
Status
defended, grade B
Date
18 June 2021
Reviewer
Committee
Ryšavý Ondřej, doc. Ing., Ph.D. (DIFS FIT BUT), předseda
Hliněná Dana, doc. RNDr., Ph.D. (DMAT FEEC BUT), člen
Kořenek Jan, doc. Ing., Ph.D. (DCSY FIT BUT), člen
Křena Bohuslav, Ing., Ph.D. (DITS FIT BUT), člen
Szőke Igor, Ing., Ph.D. (DCGM FIT BUT), člen
Citation
BOLF, René. Profilování síťových entit pro zlepšení situačního povědomí. Brno, 2021. Bachelor's Thesis. Brno University of Technology, Faculty of Information Technology. 2021-06-18. Supervised by Žádník Martin. Available from: https://www.fit.vut.cz/study/thesis/24028/
BibTeX
@bachelorsthesis{FITBT24028,
    author = "Ren\'{e} Bolf",
    type = "Bachelor's thesis",
    title = "Profilov\'{a}n\'{i} s\'{i}\v{t}ov\'{y}ch entit pro zlep\v{s}en\'{i} situa\v{c}n\'{i}ho pov\v{e}dom\'{i}",
    school = "Brno University of Technology, Faculty of Information Technology",
    year = 2021,
    location = "Brno, CZ",
    language = "czech",
    url = "https://www.fit.vut.cz/study/thesis/24028/"
}
Back to top