<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" href="/oai-pmh.xsl"?>
<OAI-PMH xmlns="http://www.openarchives.org/OAI/2.0/" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://www.openarchives.org/OAI/2.0/ http://www.openarchives.org/OAI/2.0/OAI-PMH.xsd">
  <responseDate>2026-09-19T18:34:53Z</responseDate>
  <request identifier="oai:www.ideals.illinois.edu:2142/49735" metadataPrefix="etdms" verb="GetRecord">https://www.ideals.illinois.edu/oai-pmh</request>
  <GetRecord>
    <record>
      <header>
        <identifier>oai:www.ideals.illinois.edu:2142/49735</identifier>
        <datestamp>2023-07-11</datestamp>
        <setSpec>col_2142_5131</setSpec>
        <setSpec>col_2142_16359</setSpec>
        <setSpec>com_2142_5130</setSpec>
        <setSpec>com_2142_16358</setSpec>
        <setSpec>com_2142_234</setSpec>
      </header>
      <metadata>
        <thesis xmlns="http://www.ndltd.org/standards/metadata/etdms/1.1/" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:dc="http://purl.org/dc/elements/1.1/" xsi:schemaLocation="http://www.ndltd.org/standards/metadata/etdms/1.1/ http://www.ndltd.org/standards/metadata/etdms/1.1/etdms11.xsd http://purl.org/dc/elements/1.1/ http://www.ndltd.org/standards/metadata/etdms/1.1/etdmsdc.xsd">
          <dc:contributor>Sowers, Richard B.</dc:contributor>
          <dc:contributor>Sowers, Richard B.</dc:contributor>
          <dc:contributor>Abbas, Ali E.</dc:contributor>
          <dc:contributor>Kiyavash, Negar</dc:contributor>
          <dc:contributor>Song, Renming</dc:contributor>
          <dc:creator>Kone, Roseline</dc:creator>
          <dc:date>2014-05-30T17:07:05Z</dc:date>
          <dc:date>2014-05-30T17:07:05Z</dc:date>
          <dc:date>2016-09-22T20:59:27Z</dc:date>
          <dc:date>2014-05</dc:date>
          <dc:date>2014-05-30T17:07:05Z</dc:date>
          <dc:date>2014-05</dc:date>
          <dc:description>This thesis presents three procedures to detect Distributed Denial of Service (DDoS) attacks. DDoS
attacks are known as one of the most expensive and destructive Internet threats. Assuming network
tra c is a marked Poisson process, two parametric detection models are developed. The arrival
of packet 
ows is modeled as Poisson process with cluster sizes that follows a mixture of discrete
and heavy tailed distributions. Both detection systems monitor the percentage of unknown source
IP addresses. The  rst detection model is formulated as a  xed sample size binary hypothesis
testing. The decision making is based on the Neyman-Pearson criteria. The second parametric
model is a sequential probability ratio test where the sample size is a random variable. Acceptance
and rejection boundaries are deduced based on Wald's Fundamental Identity. Given that parametric
distributions may fail to capture the complex and dynamic nature of the Internet, a third
non-parametric detection model is proposed. In addition to the percentage of unknown source IP
addresses, a second test statistic is introduced. The latter represents the mean to standard deviation
ratio of data packet sizes. The Neyman-Pearson threshold is estimated from the empirical
distribution functions of both random variables.</dc:description>
          <dc:description>Item withdrawn by Mark Zulauf (zulauf@illinois.edu) on 2014-04-23T18:00:19Z
Item was in collections:
University of Illinois Theses &amp; Dissertations (ID: 1)
No. of bitstreams: 2
Kone_Estelle.pdf: 1904919 bytes, checksum: b4b350e1618c4fd2445fbf1276a6352b (MD5)
Kone_Estelle.zip: 1200829 bytes, checksum: 3364b2849e9e39756eb130816ee96d59 (MD5)</dc:description>
          <dc:description>Made available in DSpace on 2014-05-30T17:07:05Z (GMT). No. of bitstreams: 3
Roseline_Kone.pdf: 1904919 bytes, checksum: b4b350e1618c4fd2445fbf1276a6352b (MD5)
Kone_Estelle.zip: 1200829 bytes, checksum: 3364b2849e9e39756eb130816ee96d59 (MD5)
license.txt: 4060 bytes, checksum: 53232e683498250f19800e67353cd882 (MD5)</dc:description>
          <dc:description>Item marked as restricted to the 'UIUC Users [automated]' Group (id=2) by Seth Robbins (robbins.sd@gmail.com) on 2014-05-30T17:09:55Z
Item is restricted until 2016-05-30T17:09:03Z</dc:description>
          <dc:description>Restriction data tranferred 2014-07-01T11:39:17-05:00
Original Data
Group with Access UIUC Users [automated]
Release Date: 2016-05-30 12:09:03 UTC
Reason: Author requested U of Illinois access only (OA after 2yrs) in Vireo ETD system</dc:description>
          <dc:description>U of I Only Restriction Lifted for Item 49786 on 2016-09-22T20:59:27Z.</dc:description>
          <dc:identifier>http://hdl.handle.net/2142/49735</dc:identifier>
          <dc:language>en</dc:language>
          <dc:rights>Copyright 2014 Roseline Estelle Sindolmane Kone</dc:rights>
          <dc:subject>Poisson Cluster Process</dc:subject>
          <dc:subject>Compound Pareto Distribution</dc:subject>
          <dc:subject>Binary Hypothesis Testing</dc:subject>
          <dc:subject>Sequential Detection</dc:subject>
          <dc:subject>Distributed Denial of Service (DDoS) Attacks</dc:subject>
          <dc:title>Monitoring unknown source IP addresses and packet sizes to detect DDoS attacks</dc:title>
          <dc:type>text</dc:type>
          <degree>
            <department>Industrial&amp;Enterprise Sys Eng</department>
            <departmentCode>1422</departmentCode>
            <discipline>Industrial Engineering</discipline>
            <disciplineCode>0127</disciplineCode>
            <grantor>University of Illinois at Urbana-Champaign</grantor>
            <level>Dissertation</level>
            <name>Ph.D.</name>
            <program>PHD:Industrial Enginerng -UIUC</program>
            <programCode>10KS0127PHD</programCode>
          </degree>
        </thesis>
      </metadata>
    </record>
  </GetRecord>
</OAI-PMH>
