Intrusion Detection Using Statistical Classifier Based on Packet Header Analysis | Research Square window.SnipcartSettings = { analytics: { enabled: false } }; (function() { var accessVector = localStorage.getItem('access_vector') || ''; window.dataLayer = window.dataLayer || []; if (accessVector) { window.dataLayer.push({ user: { profile: { profileInfo: { snid: accessVector } } } }); } })(); (function(w,d,s,l,i){w[l]=w[l]||[];w[l].push({'gtm.start':new Date().getTime(),event:'gtm.js'});var f=d.getElementsByTagName(s)[0],j=d.createElement(s),dl=l!='dataLayer'?'&l='+l:'';j.async=true;j.src='https://www.googletagmanager.com/gtm.js?id='+i+dl;f.parentNode.insertBefore(j,f);})(window,document,'script','dataLayer','GTM-K279D39R'); Browse Preprints In Review Journals COVID-19 Preprints AJE Video Bytes Research Tools Research Promotion AJE Professional Editing AJE Rubriq About Preprint Platform In Review Editorial Policies Our Team Advisory Board Help Center Sign In Submit a Preprint Cite Share Download PDF Research Article Intrusion Detection Using Statistical Classifier Based on Packet Header Analysis Vishnu Prasad S, Dr. B Malarkodi, Michael Kutty KG, Shiv Kumar Dhruw This is a preprint; it has not been peer reviewed by a journal. https://doi.org/ 10.21203/rs.3.rs-4424160/v1 This work is licensed under a CC BY 4.0 License Status: Posted Version 1 posted You are reading this latest preprint version Abstract From a network perspective, any attack that can prevent a network or system from performing its tasks can be considered an intrusion. Network intrusions pose a significant threat, potentially leading to damage, modification, or data loss. An Intrusion Detection System (IDS) can detect intrusions into a network. Multiple techniques have been designed to detect intrusions into a network, such as signature-based and anomaly-based techniques. Machine Learning (ML) techniques can also be used for intrusion detection, but their reliance on traffic flow parameters can introduce prediction delays. This work presents a novel statistical classifier for anomaly-based IDS that uses features extracted from packet headers to make predictions, thus avoiding such delays. The proposed technique is designed by modifying the conventional Packet Header Anomaly Detection (PHAD). In PHAD, packet headers are used to generate scores, which are compared to a threshold to make predictions. Conventional packet header-based anomaly detection techniques have the demerit of generating a lot of false alarms. The proposed approach utilizes a comprehensive set of statistical features from the scores generated by the packet header anomaly detection technique to make predictions. The proposed classifier was tested using publicly available intrusion detection datasets, and the results show that the proposed classifier can make more accurate predictions than conventional PHAD techniques without high false alarms. The proposed classifier performance was also compared and cross-verified with other techniques from the literature, and it performed better than those techniques, showcasing its superior performance in accurately classifying network attacks while minimizing false alarms. Anomaly Detection Intrusion Detection Crossdataset- analysis Packet Header-based Anomaly Detection Statistical Classification. Full Text Additional Declarations No competing interests reported. Cite Share Download PDF Status: Posted Version 1 posted You are reading this latest preprint version Research Square lets you share your work early, gain feedback from the community, and start making changes to your manuscript prior to peer review in a journal. As a division of Research Square Company, we’re committed to making research communication faster, fairer, and more useful. We do this by developing innovative software and high quality services for the global research community. Our growing team is made up of researchers and industry professionals working together to solve the most critical problems facing scientific publishing. Also discoverable on Platform About Our Team In Review Editorial Policies Advisory Board Help Center Resources Author Services Accessibility API Access RSS feed Manage Cookie Preferences © Research Square 2026 | ISSN 2693-5015 (online) Privacy Policy Terms of Service Do Not Sell My Personal Information {"props":{"pageProps":{"initialData":{"identity":"rs-4424160","acceptedTermsAndConditions":true,"allowDirectSubmit":true,"archivedVersions":[],"articleType":"Research Article","associatedPublications":[],"authors":[{"id":306554790,"identity":"da045600-ce42-4491-8b31-7a481d1f243e","order_by":0,"name":"Vishnu Prasad S","email":"data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAZAAAAAyAQMAAABI0h/eAAAABlBMVEX///8AAABVwtN+AAAACXBIWXMAAA7EAAAOxAGVKw4bAAABEklEQVRIiWNgGAWjYDACZgY2OFsCRPCDiIQCUrRINoC0GOC1B02LwQEwiVu9wXH2Z48L2+7k8/cffnjzB4ONvPH51YkfHhgwyPOLHcCu5TCPufHMtmeWM26kGVvzMKQZbrvxdrME0GGGM2cnYNUi2czDJs3bdtiA4QaDmTQDw+EEsxtnN4C0JBjcxqWF/RlYi/z5498kfzD8TzCecXbzD3xa+JmBhoO0GBzIMZPgYTiQYMDfuw2vLfzMPGbSPOeeGRjeyCm25jFINpxxg3ebRYKBBE6/sPEffybNU3bHQO788Y03f1TYyfP3n90MZNjI80tj1wIFB6A0KDokwCol8ClH1gJ26wEcikbBKBgFo2CkAgBu0FlmHyCtsgAAAABJRU5ErkJggg==","orcid":"","institution":"National Institute of Technology Tiruchirappalli","correspondingAuthor":true,"prefix":"","firstName":"Vishnu","middleName":"Prasad","lastName":"S","suffix":""},{"id":306554791,"identity":"3952c88f-446f-43c3-b57c-226f2e8904aa","order_by":1,"name":"Dr. B Malarkodi","email":"","orcid":"","institution":"National Institute of Technology Tiruchirappalli","correspondingAuthor":false,"prefix":"Dr.","firstName":"B","middleName":"","lastName":"Malarkodi","suffix":""},{"id":306554792,"identity":"38525119-13bc-4ec5-b018-03a01cc5ceca","order_by":2,"name":"Michael Kutty KG","email":"","orcid":"","institution":"Centre for Artificial Intelligence and Robotics","correspondingAuthor":false,"prefix":"","firstName":"Michael","middleName":"Kutty","lastName":"KG","suffix":""},{"id":306554794,"identity":"1c6aec23-9e01-4495-b1bc-110c396eefa3","order_by":3,"name":"Shiv Kumar Dhruw","email":"","orcid":"","institution":"Centre for Artificial Intelligence and Robotics","correspondingAuthor":false,"prefix":"","firstName":"Shiv","middleName":"Kumar","lastName":"Dhruw","suffix":""}],"badges":[],"createdAt":"2024-05-15 09:33:04","currentVersionCode":1,"declarations":"","doi":"10.21203/rs.3.rs-4424160/v1","doiUrl":"https://doi.org/10.21203/rs.3.rs-4424160/v1","draftVersion":[],"editorialEvents":[],"editorialNote":"","failedWorkflow":false,"files":[{"id":57773365,"identity":"eac44d9c-12f1-4f1c-b282-ae43de533c4b","added_by":"auto","created_at":"2024-06-05 12:47:32","extension":"pdf","order_by":1,"title":"","display":"","copyAsset":false,"role":"manuscript-pdf","size":908490,"visible":true,"origin":"","legend":"","description":"","filename":"VishnuStatisticalClassifiermanuscript.pdf","url":"https://assets-eu.researchsquare.com/files/rs-4424160/v1_covered_9baecb39-91da-46a4-9690-8daf7ea6275b.pdf"}],"financialInterests":"No competing interests reported.","formattedTitle":"\u003cp\u003eIntrusion Detection Using Statistical Classifier Based on Packet Header Analysis\u003c/p\u003e","fulltext":[],"fulltextSource":"","fullText":"","funders":[],"hasAdminPriorityOnWorkflow":false,"hasManuscriptDocX":false,"hasOptedInToPreprint":true,"hasPassedJournalQc":"","hasAnyPriority":false,"hideJournal":true,"highlight":"","institution":"","isAcceptedByJournal":false,"isAuthorSuppliedPdf":true,"isDeskRejected":"","isHiddenFromSearch":false,"isInQc":false,"isInWorkflow":false,"isPdf":true,"isPdfUpToDate":true,"isWithdrawnOrRetracted":false,"journal":{"display":true,"email":"
[email protected]","identity":"researchsquare","isNatureJournal":false,"hasQc":true,"allowDirectSubmit":true,"externalIdentity":"","sideBox":"","snPcode":"","submissionUrl":"/submission","title":"Research Square","twitterHandle":"researchsquare","acdcEnabled":true,"dfaEnabled":false,"editorialSystem":"","reportingPortfolio":"","inReviewEnabled":false,"inReviewRevisionsEnabled":true},"keywords":"Anomaly Detection, Intrusion Detection, Crossdataset- analysis, Packet Header-based Anomaly Detection, Statistical Classification.","lastPublishedDoi":"10.21203/rs.3.rs-4424160/v1","lastPublishedDoiUrl":"https://doi.org/10.21203/rs.3.rs-4424160/v1","license":{"name":"CC BY 4.0","url":"https://creativecommons.org/licenses/by/4.0/"},"manuscriptAbstract":"From a network perspective, any attack that can prevent a network or system from performing its tasks can be considered an intrusion. Network intrusions pose a significant threat, potentially leading to damage, modification, or data loss. An Intrusion Detection System (IDS) can detect intrusions into a network. Multiple techniques have been designed to detect intrusions into a network, such as signature-based and anomaly-based techniques. Machine Learning (ML) techniques can also be used for intrusion detection, but their reliance on traffic flow parameters can introduce prediction delays. This work presents a novel statistical classifier for anomaly-based IDS that uses features extracted from packet headers to make predictions, thus avoiding such delays. The proposed technique is designed by modifying the conventional Packet Header Anomaly Detection (PHAD). In PHAD, packet headers are used to generate scores, which are compared to a threshold to make predictions. Conventional packet header-based anomaly detection techniques have the demerit of generating a lot of false alarms. The proposed approach utilizes a comprehensive set of statistical features from the scores generated by the packet header anomaly detection technique to make predictions. The proposed classifier was tested using publicly available intrusion detection datasets, and the results show that the proposed classifier can make more accurate predictions than conventional PHAD techniques without high false alarms. The proposed classifier performance was also compared and cross-verified with other techniques from the literature, and it performed better than those techniques, showcasing its superior performance in accurately classifying network attacks while minimizing false alarms.","manuscriptTitle":"Intrusion Detection Using Statistical Classifier Based on Packet Header Analysis","msid":"","msnumber":"","nonDraftVersions":[{"code":1,"date":"2024-05-29 05:47:38","doi":"10.21203/rs.3.rs-4424160/v1","editorialEvents":[{"type":"communityComments","content":0}],"status":"published","journal":{"display":true,"email":"
[email protected]","identity":"researchsquare","isNatureJournal":false,"hasQc":true,"allowDirectSubmit":true,"externalIdentity":"","sideBox":"","snPcode":"","submissionUrl":"/submission","title":"Research Square","twitterHandle":"researchsquare","acdcEnabled":true,"dfaEnabled":false,"editorialSystem":"","reportingPortfolio":"","inReviewEnabled":false,"inReviewRevisionsEnabled":true}}],"origin":"","ownerIdentity":"03c425fb-d028-4616-b664-3e485c832b40","owner":[],"postedDate":"May 29th, 2024","published":true,"recentEditorialEvents":[],"rejectedJournal":[],"revision":"","amendment":"","status":"posted","subjectAreas":[],"tags":[],"updatedAt":"2024-06-05T12:39:24+00:00","versionOfRecord":[],"versionCreatedAt":"2024-05-29 05:47:38","video":"","vorDoi":"","vorDoiUrl":"","workflowStages":[]},"version":"v1","identity":"rs-4424160","journalConfig":"researchsquare"},"__N_SSP":true},"page":"/article/[identity]/[[...version]]","query":{"redirect":"/article/rs-4424160","identity":"rs-4424160","version":["v1"]},"buildId":"qtupq5eGEP_6zYnWcrvyt","isFallback":false,"isExperimentalCompile":false,"dynamicIds":[84888],"gssp":true,"scriptLoader":[]}
Text is read by the "Ask this paper" AI Q&A widget below.
Extraction quality varies by source — PMC NXML preserves structure
cleanly, OA-HTML may include some navigation residue, and OA-PDF can
have broken hyphenation. The publisher copy
(via DOI)
is the canonical version.