Repository logo
Log In(current)
  1. Home
  2. Colleges & Schools
  3. Graduate School
  4. Doctoral Dissertations
  5. Federated Agentless Detection of Endpoints Using Behavioral and Characteristic Modeling
Details

Federated Agentless Detection of Endpoints Using Behavioral and Characteristic Modeling

Date Issued
December 1, 2021
Author(s)
Kodituwakku, Hansaka Angel Dias Edirisinghe  
Advisor(s)
Jens Gregor
Additional Advisor(s)
Jens Gregor
Hamparsum Bozdogan
Jinyuan Sun
Jian Liu
Tim Shimeall
Permanent URI
https://trace.tennessee.edu/handle/20.500.14382/28306
Abstract

During the past two decades computer networks and security have evolved that, even though we use the same TCP/IP stack, network traffic behaviors and security needs have significantly changed. To secure modern computer networks, complete and accurate data must be gathered in a structured manner pertaining to the network and endpoint behavior. Security operations teams struggle to keep up with the ever-increasing number of devices and network attacks daily. Often the security aspect of networks gets managed reactively instead of providing proactive protection. Data collected at the backbone are becoming inadequate during security incidents. Incident response teams require data that is reliably attributed to each individual endpoint over time. With the current state of dissociated data collected from networks using different tools it is challenging to correlate the necessary data to find origin and propagation of attacks within the network. Critical indicators of compromise may go undetected due to the drawbacks of current data collection systems leaving endpoints vulnerable to attacks. Proliferation of distributed organizations demand distributed federated security solutions. Without robust data collection systems that are capable of transcending architectural and computational challenges, it is becoming increasingly difficult to provide endpoint protection at scale. This research focuses on reliable agentless endpoint detection and traffic attribution in federated networks using behavioral and characteristic modeling for incident response.

Subjects

cybersecurity

endpoint modeling

network security

agentless

endpoint detection

spoofing

data collection syste...

incident response

Disciplines
Other Computer Engineering
Degree
Doctor of Philosophy
Major
Computer Engineering
File(s)
Thumbnail Image
Name

Dissertation_V12.docx

Size

2.91 MB

Format

Microsoft Word XML

Checksum (MD5)

f5bafbfc5d04501d633b33216f987057

Thumbnail Image
Name

auto_convert.pdf

Size

1.99 MB

Format

Adobe PDF

Checksum (MD5)

71de957f13afb9ed024532bed3b4638f


University Libraries

1015 Volunteer Boulevard
Knoxville, TN 37996
865-974-4351

Map & Directions
Donate to the Libraries
  • About
  • John C. Hodges Society
  • Speaking Volumes magazine
  • Outreach
  • Directory
  • Employment
  • Policies
  • Library Intranet
University of Tennessee power T logo

The University of Tennessee, Knoxville
Knoxville, Tennessee 37996
865-974-1000

Events
A-Z
Apply
Privacy
Map
Directory
Give to UT
Accessibility

Built with DSpace-CRIS software - Extension maintained and optimized by 4Science