Executive Summary


Over the last decade, system security threats have evolved from human intruders to sophisticated malware. With the evolution of these attack methodologies, the field of intrusion detection has inevitably evolved with detection of malicious network attacks becoming its main focus. This research project includes indigenous design and development of a state-of-the- art enterprise network security solution in Pakistan. This security solution will detect zero-day (previously unknown) attacks in real-time. The solution consists of two main modules: i) An active anomaly detector that will be deployed at the network perimeter; ii) A passive network monitor that can detect Internet-scale as well as targeted threats and will also facilitate attack forensics. The proposed network security software will be tested on academic and industrial networks in Pakistan. After its development and testing in the end-user environment, this software solution will be made publicly available under an open-source license. Due to its cutting-edge nature, this software solution has the potential of establishing an international repute for Pakistan in the highly profitable and potent network security market. The key benefits of this project are: