IMT4204

Intrusion Detection in Physical and Virtual Networks

Autumn

Trondheim and Gjøvik

English

Overview

19 candidates

Average grade

C

3.11

0.47

Pass rate

100%

10 points

Grade distribution
Average over time
Pass rate over time

About this course

Content

IDS/IPS definition and classification -Basic elements of attacks and their detection

Misuse detection systems (search algorithms and applications in IDS)

Anomaly detection systems (machine learning basics: principles, measures, performance evaluation, method combinations, basics of artificial neural networks, clustering (hierarchical and partitional) and supervised learning in IDS)

Testing IDS and measuring their performances

Computational complexity-theoretic and information-theoretic IDS models and quality criteria

Intrusion detection in virtual networks.

Learning outcomes

Knowledge: -Possesses advanced knowledge in detection/prevention of intrusions in computer systems and networks, in particular: application of advanced search algorithms in intrusion detection, unsupervised and supervised learning methods used in these systems, computational complexity-theoretic modeling, information-theoretic modeling of intrusion detection/prevention systems, and intrusion detection in virtual networks. -Possesses thorough knowledge about theory and scientific methods relevant for intrusion detection. -Is capable of applying his/her knowledge in design and analysis of intrusion detection/prevention systems.

Skills: -Is capable of analyzing existing theories, methods and interpretations in the field of intrusion detection and working independently on solving theoretical and practical problems. -Can use relevant scientific methods in independent research and development in intrusion detection. -Is capable of performing critical analysis of various literature sources and applying them in structuring and formulating scientific reasoning in the field of intrusion detection and prevention. -Is capable of carrying out an independent limited research or development project in intrusion detection under supervision, following the applicable ethical rules.

General competence: -Is capable of analyzing relevant professional and research ethical problems in the field of intrusion detection. -Is capable of applying his/her knowledge and skills in new fields, in order to accomplish advanced tasks and projects. -Can work independently and is familiar with terminology in the field of intrusion detection and prevention. -Is capable of discussing professional problems in the field of intrusion detection and prevention, both with specialists and with general audience. -Is capable of contributing to innovation and innovation processes.

The course addresses the following UN Sustainable Development Goals (SDG):

Goal 7, target 7.3, also related to the goal 12, target 2 - double the global rate of improvement in energy efficiency / achieve the sustainable management and efficient use of natural resources - by designing fast and efficient big data processing algorithms, we reduce the energy consumption ensuring at the same time reliability and security of network communications.

Goal 9, target 9.5 - Enhance scientific research, upgrade the technological capabilities of industrial sectors in all countries - studying the algorithms for host and network intrusion detection, the students improve their skills and competence in many research fields, such as computer science, mathematics, statistics, etc. This contributes to taking the quality of research and development in their countries of origin to a higher level.

Handling AI in the course:

The students are encouraged to use AI in the preparation of the report related to the project, provided they claim how they used AI tools in this process. The project task is a complex numerical problem-solving task, for which using AI tools to solve it completely is highly unlikely. Thus, the probability that using AI in the preparation of the project report will have negative influence on reaching the learning outcomes is negligible.

Using AI on the written exam is impossible, since the written exam is carried out at NTNU premisses under control.

Teaching methods

-Lectures -Lab work -Numerical exercises

Additional information: -The course will be made accessible for both campus (Gjøvik/Trondheim) and remote students. Every student is free to choose the pedagogic arrangement form that is best fitted for her/his own requirements. The lectures in the course will be given on campus Gjøvik and are open for both categories of students. All the lectures will also be available on Internet through the learning management system.

Compulsory requirements: None.