Publication Date
Spring 2026
Degree Type
Master's Project
Degree Name
Master of Science in Computer Science (MSCS)
Department
Computer Science
First Advisor
Fabio Di Troia
Second Advisor
Amith Kamath Belman
Third Advisor
Sharan Reddy Konda
Keywords
Network Intrusion Detection, Benford’s Law, Anomaly Detection, Statis- tical Analysis, CICIDS2017.
Abstract
Traditional signature network intrusion detection is not effective against zero-day attacks. So this thesis presents a novel, signature-free approach using Benford’s Law to find anomalies based on the natural frequency of leading digits. The methodology follows a three-phase framework such as selecting features that best fit with Benford’s Law (e.g., Flow Bytes/s), then applying MAD-based conformity testing on sliding windows, and lastly fusing evidence via Fisher’s Combined Probability Test. We experiment and evaluate this approach on CICIDS-2017 dataset, the system achieves 84.1% recall and an F1-score of 0.75 showing promising results. Considering that it shows exceptional performance against volumetric attacks, detecting DoS, DDoS, and PortScans with rates exceeding 99%. After the experiment, we learn that automated attack tools deviate from natural digit distributions which show violation of Benford’s Law. This finding validates Benford’s Law as a mathematical foundation for identifying evolving network threats. The research demonstrates that Benford’s Law provides a mathematically grounded foundation for detecting network anomalies, offering approach to current existing security mechanisms which can identify both known and previously unseen patterns from attack.
Recommended Citation
Ong, Huy, "Network Intrusion Detection Using Benford’s Law and Statistical Distance Functions" (2026). Master's Projects. 1823.
DOI: https://doi.org/10.31979/etd.7suv-akfx
https://scholarworks.sjsu.edu/etd_projects/1823