Abstract #301652


The views expressed here are those of the individual authors
and not necessarily those of the ASA or its board, officers, or staff.


Back to main JSM 2002 Program page



JSM 2002 Abstract #301652
Activity Number: 372
Type: Topic Contributed
Date/Time: Thursday, August 15, 2002 : 8:30 AM to 10:20 AM
Sponsor: Section on Statistical Computing*
Abstract - #301652
Title: Using Statistics to Help People Understand Network Intrusion Detections
Author(s): John Rigsby*+ and William Ralph
Affiliation(s): NSWCDD and NSWCDD
Address: 17320 Dahlgren Road B10, Dahlgren, Virginia, 22448, USA
Keywords: statistics ; network ; intrusion ; detection
Abstract:

SHADOW, Secondary Heuristic Analysis for Defensive Online Warfare, is a network intrusion detection system written by William Ralph at the Naval Surface Warfare Center Dahlgren Division. SHADOW was designed to use free software and run on inexpensive hardware. It is a project in constant development growing in different directions. A network statistics page, written by William Ralph and John Rigsby, is currently being internally tested here at our lab. The page provides the user with the capability to examine rudimentary statistics about network traffic. This page takes network traffic dump files (tcpdump files) and generates simple statistics about bandwidth usage, IP, TCP, UDP, ICMP, and other protocol-related statistics. It also generates information about IP address space usage including private, multicast, and reserved ranges. The major use of the tool is to bring forth a sense of accountability for network bandwidth usage. The program groups hosts based on whether they are internal or external systems and network bandwidth utilization. The statistics page presents the network audit information in an easy to understand format with the capability for drill down.


  • The address information is for the authors that have a + after their name.
  • Authors who are presenting talks have a * after their name.

Back to the full JSM 2002 program

JSM 2002

For information, contact meetings@amstat.org or phone (703) 684-1221.

If you have questions about the Continuing Education program, please contact the Education Department.

Revised March 2002