Data analytics for intrusion detection

Assignment Help Computer Networking
Reference no: EM132221555 , Length: word count:1500

Data analytics for intrusion detection

Purpose of the assessment (with ULO Mapping)

This assignment assesses the following Unit Learning Outcomes; students should be able to demonstrate their achievements in them.
c) Evaluate intelligent security solutions based on data analytics
d) Analyse and interpret results from descriptive and predictive data analysis

Assignment Overview

You are hired by the Purehacking Pty Ltd (a popular penetration testing company in Australia) to consult an accounting company which requested advanced instruction detection system for their internal network. The accounting firm had suffered malicious hacking attack which compromised their client's information and released it on the dark web. The reputation of the accounting company was severely damaged, and the managing director of the accounting firm was determined not to tolerate any such future attacks that can jeopardize his business.

Your supervisor at Purehacking wishes to try out an advanced data analytic tool to improve the network instruction detection at the accounting company.

Your supervisor has asked you to test out a few data analytics techniques available on the market and evaluate their performance in network intrusion detection.

To provide a fair comparison of security performance, your supervisor is recommending you consider a network security benchmark data such as the popular KDD99 dataset.

Your supervisor will make recommendation to the accounting firm based on your technical findings and report.

Your tasks are to:

1. Perform intrusion detection using the available data analytics techniques using WEKA or other platforms.

2. Evaluate the performance of data analytic techniques in intrusion detection using comparative analysis

3. Recommend the security solution using the selected data analytic technique.

In consultation with your lecturer, you are to choose at least three data analytic techniques for network intrusion detection and prepare a technical research report. Follow the marking guide to prepare your report.

Section 1: Data Analytic Tools and Techniques
In this section, your task is to complete and write a report on the following:

1. Install/deploy the data analytic platform of your choice (on Win8 VM on VirtualBox).

2. Demonstrate the use of at least two data analytic techniques (e.g. decision tree, clustering or other techniques) - you are free to use any sample testing data to demonstrate your skills and knowledge.

3. Lab demonstration: Must explain how each tool technique works in your lab prior to week 11. Data can be anything including Iris data set.

Section 2: Data Analytic for Network Intrusion Detection

You are to perform the following tasks and write a full report on your outcomes:

1. Convert the benchmark data suitable for the data analytic tools and platform of your choice. Explain the differences in the available data format for data analytics.

2. Select the features with rationale (external reference or your own reasoning).

3. Create training and testing data samples

4. Evaluate and select the data analytic techniques for testing

5. Classify the network intrusion given the sample data

6. Evaluate the performance of intrusion detection using the available tools and technologies (e.g. confusion matrix).

7. Identify the limitation of overfitting

8. Evaluate and analyse the use of ensemble tools

9. Recommend the data analytic solution for the network intrusion detection.

10. Discuss future research work given time and resources

Attachment:- Assignment.rar

Reference no: EM132221555

Questions Cloud

What technology did they implement : Identify two organizations that have benefited from implementing a technology that improved their data governance.
Explain when demand would be perfectly elastic : Price elasticity of demand measures the responsiveness of quantity demanded of a product to a change in the price of that product.
Why do we need an automated tool for sql injection : Discuss sqlmap, an automated tool for sql injection and database takeover in 500 words or more. How does it work? Where do you get it? How much does it cost?
What happened to the english population in the 19th century : Consider whether you are a Malthusian pessimist or Jeffersonian optimist. Why? What happened to the English Population in the 19th century?
Data analytics for intrusion detection : MN623 Cyber Security and Analytics - Data analytics for intrusion detection - Perform intrusion detection using the available data analytics techniques
Describe the written or non-written policy : Describe the written or non-written policy in place for your home network. After you post it, compare yours with other classmates' policies and discuss why one.
Define how to implement a new erp system : You are part of Enterprise Risk Management and you organization is planning to implement a new ERP system. You are going from Microsoft Dynamics to SAP.
To what degree do you think it likely that the gloomy : The reason for the dismal theories of Ricardo and Malthus not becoming true, Heilbroner suggests, is that we have been saved by technology.
What about off-site storage of backups : There have been several incidents lately in which backup media containing personal customer information were lost or stolen. How should backup media be secured?



1/23/2019 1:37:40 AM

Implementation All elements are present and very well Implemented. Components present with good cohesive Components present and mostly well integrated Most components present Proposal lacks structure. Explanation All elements are present and well integrated. Components present with good cohesion Components present and mostly well integrated Most components present Lacks structure.


1/23/2019 1:37:33 AM

Grade Mark HD 80%+ D 70%-79% CR 60%-69% P 50%-59% Fail < 50% Excellent Very Good Good Satisfactory Unsatisfactory Evaluation Logic is clear and easy to follow with strong arguments Consistency logical and convincing Mostly consistent and convincing Adequate cohesion and conviction Argument is confused and disjointed


1/23/2019 1:37:17 AM

Section 2 – Data analytics 1. Convert the benchmark data suitable for the data analytic tools and platform of your choice. Explain the differences in the available data format for data analytics. 2. Select the features with rationale (external reference or your own reasoning). 3. Create training and testing data samples 4. Evaluate and select the data analytic techniques for testing 5. Classify the network intrusion given the sample data 6. Evaluate the performance of intrusion detection using the available tools and technologies (e.g. confusion matrix). 7. Identify the limitation of overfitting 8. Evaluate and analyse the use of ensemble tools 9. Recommend the data analytic solution for the network intrusion detection. 10. Discuss future research work given time and resources 5 practical report 5 5 5 5 5 5 5 5 5


1/23/2019 1:37:02 AM

Report structure and report presentation Compile a written report of the above along with your evaluations and recommendations. The report must contain several screenshots of evidence and a short description for each snapshot that provides proof that you completed the work. 10


1/23/2019 1:36:49 AM

Marking criteria: Section to be included in the report and demonstration Description of the section Marks Section 1 - Install and deploy Introduction to each of your data analytic tools and platforms 3 Section 1- Explain and evaluate Full explanation of each data analytic techniques with support from either own evidence(s) and/or from other online sources. Advantages and disadvantages of each data analytic techniques (of your choice). 5 Section 1 - Lab demonstration To obtain full marks, students need to implement and demonstrate the use of at least two data analytic techniques in any platform of your choice. You may choose to use any testing data for demonstration. 10


1/23/2019 1:36:38 AM

Due Date Friday 11:55 PM, Week 11 Submission Guidelines • All work must be submitted on Moodle by the due date along with a completed Assignment Cover Page. • The assignment must be in MS Word format, 1.5 spacing, 11-pt Calibri (Body) font and 2 cm margins on all four sides of your page with appropriate section headings. • Reference sources must be cited in the text of the report, and listed appropriately at the end in a reference list using IEEE referencing style.

Write a Review

Computer Networking Questions & Answers

  Networking and types of networking

This assignment explains the networking features, different kinds of networks and also how they are arranged.

  National and Global economic environment and ICICI Bank

While working in an economy, it has a separate identity but cannot operate insolently.

  Ssh or openssh server services

Write about SSH or OpenSSH server services discussion questions

  Network simulation

Network simulation on Hierarchical Network Rerouting against wormhole attacks

  Small internet works

Prepare a network simulation

  Solidify the concepts of client/server computing

One-way to solidify the concepts of client/server computing and interprocess communication is to develop the requirements for a computer game which plays "Rock, Paper, Scissors" using these techniques.

  Identify the various costs associated with the deployment

Identify the various costs associated with the deployment, operation and maintenance of a mobile-access system. Identify the benefits to the various categories of user, arising from the addition of a mobile-access facility.

  Describe how the modern view of customer service

Describe how the greater reach of telecommunication networks today affects the security of resources which an organisation provides for its employees and customers.

  Technology in improving the relationship building process

Discuss the role of Technology in improving the relationship building process Do you think that the setting of a PR department may be helpful for the ISP provider? Why?

  Remote access networks and vpns

safekeeping posture of enterprise (venture) wired and wireless LANs (WLANs), steps listed in OWASP, Securing User Services, IPV4 ip address, IPV6 address format, V4 address, VPN, Deploying Voice over IP, Remote Management of Applications and Ser..


problems of IPV, DNS server software, TCP SYN attack, Ping of Death, Land attack, Teardrop attack, Smurf attack, Fraggle attack

  Outline the difference between an intranet and an extranet

Outline the difference between an intranet and an extranet A programmer is trying to produce an applet with the display shown in Figure 1 below such that whenever one of the checkboxes is selected the label changes to indicate correctly what has..

Free Assignment Quote

Assured A++ Grade

Get guaranteed satisfaction & time on delivery in every assignment order you paid with us! We ensure premium quality solution document along with free turntin report!

All rights reserved! Copyrights ©2019-2020 ExpertsMind IT Educational Pvt Ltd