Publication Date

Spring 2026

Degree Type

Master's Project

Degree Name

Master of Science in Computer Science (MSCS)

Department

Computer Science

First Advisor

Fabio Di Troia

Second Advisor

Amith Kamath Belman

Third Advisor

Sharan Reddy Konda

Keywords

Network Intrusion Detection, Benford’s Law, Anomaly Detection, Statis- tical Analysis, CICIDS2017.

Abstract

Traditional signature network intrusion detection is not effective against zero-day attacks. So this thesis presents a novel, signature-free approach using Benford’s Law to find anomalies based on the natural frequency of leading digits. The methodology follows a three-phase framework such as selecting features that best fit with Benford’s Law (e.g., Flow Bytes/s), then applying MAD-based conformity testing on sliding windows, and lastly fusing evidence via Fisher’s Combined Probability Test. We experiment and evaluate this approach on CICIDS-2017 dataset, the system achieves 84.1% recall and an F1-score of 0.75 showing promising results. Considering that it shows exceptional performance against volumetric attacks, detecting DoS, DDoS, and PortScans with rates exceeding 99%. After the experiment, we learn that automated attack tools deviate from natural digit distributions which show violation of Benford’s Law. This finding validates Benford’s Law as a mathematical foundation for identifying evolving network threats. The research demonstrates that Benford’s Law provides a mathematically grounded foundation for detecting network anomalies, offering approach to current existing security mechanisms which can identify both known and previously unseen patterns from attack.

Available for download on Saturday, May 22, 2027

Share

COinS